CVE-2013-0865
Publication date 23 November 2013
Last updated 24 July 2024
Ubuntu priority
The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Video file, which triggers an out-of-bounds write.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | ||
ffmpeg-extra | ||
libav | ||
libav-extra | ||
Notes
mdeslaur
libav and ffmpeg codebases have diverged to the point of not being able to track both using the same CVE numbers. Marking this CVE as not-affected for libav.