7.5
CVSSv2

CVE-2013-0894

Published: 23/02/2013 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg up to and including 1.1.3, as used in Google Chrome prior to 25.0.1364.97 on Windows and Linux and prior to 25.0.1364.99 on Mac OS X and other products, allows remote malicious users to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

ffmpeg ffmpeg

opensuse opensuse 12.2

opensuse opensuse 12.1

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

Vendor Advisories

Debian Bug report logs - #703200 libav: CVE-2013-0894 CVE-2013-2277 CVE-2013-2495 CVE-2013-2496 Package: src:libav; Maintainer for src:libav is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sat, 16 Mar 2013 20:12:02 UTC Sev ...
Libav could be made to crash or run programs as your login if it opened a specially crafted file ...