Vulnerability Name:
CVE-2013-4265 (CCN-86579)
Assigned:
2013-08-21
Published:
2013-08-21
Updated:
2016-12-03
Summary:
The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.
http://cwe.mitre.org/data/definitions/476.html
"CWE-476: NULL Pointer Dereference"
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Low
CVSS v2 Severity:
10.0 High
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
)
7.4 High
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
4.3 Medium
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P
)
3.2 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Denial of Service
References:
Source: MITRE
Type: CNA
CVE-2013-4265
Source: CCN
Type: FFmpeg Web site
FFmpeg
Source: CCN
Type: SA54541
FFmpeg Multiple Vulnerabilities
Source: CONFIRM
Type: UNKNOWN
http://www.ffmpeg.org/security.html
Source: MLIST
Type: UNKNOWN
[oss-security] 20130821 Re: CVE Request: FFmpeg 2.0.1 multiple problems
Source: CCN
Type: BID-61934
FFmpeg CVE-2013-4265 Memory Corruption Vulnerability
Source: XF
Type: UNKNOWN
ffmpeg-avreallocparray-dos(86579)
Source: CCN
Type: FFmpeg GIT Repository
avutil/mem: Fix flipped condition
Source: CONFIRM
Type: Exploit, Patch
https://github.com/FFmpeg/FFmpeg/commit/c94f9e854228e0ea00e1de8769d8d3f7cab84a55
Source: GENTOO
Type: UNKNOWN
GLSA-201603-06
Vulnerable Configuration:
Configuration 1
:
cpe:/a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5.4.5:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.5.4.6:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.6:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.6.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.6.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.6.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.5:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.6:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.7:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.8:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.9:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.11:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.7.12:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.0:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.5:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.5.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.5.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.6:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.7:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.8:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.10:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.8.11:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.9:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.9.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.10:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.10.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.10.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:0.11:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.0:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.1.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.1.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.1.3:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.1.4:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.2:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:1.2.1:*:*:*:*:*:*:*
OR
cpe:/a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
(Version <= 2.0)
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:com.ubuntu.precise:def:20134265000
V
CVE-2013-4265 on Ubuntu 12.04 LTS (precise) - medium.
2013-11-23
BACK
ffmpeg
ffmpeg 0.3
ffmpeg
ffmpeg 0.3.1
ffmpeg
ffmpeg 0.3.2
ffmpeg
ffmpeg 0.3.3
ffmpeg
ffmpeg 0.3.4
ffmpeg
ffmpeg 0.4.0
ffmpeg
ffmpeg 0.4.2
ffmpeg
ffmpeg 0.4.3
ffmpeg
ffmpeg 0.4.4
ffmpeg
ffmpeg 0.4.5
ffmpeg
ffmpeg 0.4.6
ffmpeg
ffmpeg 0.4.7
ffmpeg
ffmpeg 0.4.8
ffmpeg
ffmpeg 0.5
ffmpeg
ffmpeg 0.5.1
ffmpeg
ffmpeg 0.5.2
ffmpeg
ffmpeg 0.5.3
ffmpeg
ffmpeg 0.5.4
ffmpeg
ffmpeg 0.5.4.5
ffmpeg
ffmpeg 0.5.4.6
ffmpeg
ffmpeg 0.6
ffmpeg
ffmpeg 0.6.1
ffmpeg
ffmpeg 0.6.2
ffmpeg
ffmpeg 0.6.3
ffmpeg
ffmpeg 0.7
ffmpeg
ffmpeg 0.7.1
ffmpeg
ffmpeg 0.7.2
ffmpeg
ffmpeg 0.7.3
ffmpeg
ffmpeg 0.7.4
ffmpeg
ffmpeg 0.7.5
ffmpeg
ffmpeg 0.7.6
ffmpeg
ffmpeg 0.7.7
ffmpeg
ffmpeg 0.7.8
ffmpeg
ffmpeg 0.7.9
ffmpeg
ffmpeg 0.7.11
ffmpeg
ffmpeg 0.7.12
ffmpeg
ffmpeg 0.8.0
ffmpeg
ffmpeg 0.8.1
ffmpeg
ffmpeg 0.8.2
ffmpeg
ffmpeg 0.8.5
ffmpeg
ffmpeg 0.8.5.3
ffmpeg
ffmpeg 0.8.5.4
ffmpeg
ffmpeg 0.8.6
ffmpeg
ffmpeg 0.8.7
ffmpeg
ffmpeg 0.8.8
ffmpeg
ffmpeg 0.8.10
ffmpeg
ffmpeg 0.8.11
ffmpeg
ffmpeg 0.9
ffmpeg
ffmpeg 0.9.1
ffmpeg
ffmpeg 0.10
ffmpeg
ffmpeg 0.10.3
ffmpeg
ffmpeg 0.10.4
ffmpeg
ffmpeg 0.11
ffmpeg
ffmpeg 1.0
ffmpeg
ffmpeg 1.1.1
ffmpeg
ffmpeg 1.1.2
ffmpeg
ffmpeg 1.1.3
ffmpeg
ffmpeg 1.1.4
ffmpeg
ffmpeg 1.2
ffmpeg
ffmpeg 1.2.1
ffmpeg
ffmpeg *