Vulnerability Name:

CVE-2013-7020 (CCN-89453)

Assigned:2013-11-29
Published:2013-11-29
Updated:2017-01-07
Summary:The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-7020

Source: CCN
Type: FFmpeg Web site
FFmpeg Security

Source: CONFIRM
Type: Vendor Advisory
http://ffmpeg.org/security.html

Source: MLIST
Type: Mailing List, Patch, Third Party Advisory
[oss-security] 20131126 CVE Request: FFmpeg 2.1 multiple problems

Source: MLIST
Type: Mailing List, Patch, Third Party Advisory
[oss-security] 20131208 Re: CVE Request: FFmpeg 2.1 multiple problems

Source: CCN
Type: SA55802
FFmpeg Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
61389

Source: DEBIAN
Type: Third Party Advisory
DSA-3027

Source: MANDRIVA
Type: Broken Link
MDVSA-2014:227

Source: XF
Type: UNKNOWN
ffmpeg-readheader-ffv1dec-dos(89453)

Source: CONFIRM
Type: Issue Tracking, Patch
https://github.com/FFmpeg/FFmpeg/commit/b05cd1ea7e45a836f7f6071a716c38bb30326e0f

Source: GENTOO
Type: UNKNOWN
GLSA-201603-06

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.8:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.9:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.11:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.7.12:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.8:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.10:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.11:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.9:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.10:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.10.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.10.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.11:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* (Version <= 2.0.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:6.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ffmpeg:ffmpeg:2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:26327
    P
    DSA-3027-1 libav - security update
    2014-11-10
    BACK
    ffmpeg ffmpeg 0.3
    ffmpeg ffmpeg 0.3.1
    ffmpeg ffmpeg 0.3.2
    ffmpeg ffmpeg 0.3.3
    ffmpeg ffmpeg 0.3.4
    ffmpeg ffmpeg 0.4.0
    ffmpeg ffmpeg 0.4.2
    ffmpeg ffmpeg 0.4.3
    ffmpeg ffmpeg 0.4.4
    ffmpeg ffmpeg 0.4.5
    ffmpeg ffmpeg 0.4.6
    ffmpeg ffmpeg 0.4.7
    ffmpeg ffmpeg 0.4.8
    ffmpeg ffmpeg 0.4.9 pre1
    ffmpeg ffmpeg 0.5
    ffmpeg ffmpeg 0.5.1
    ffmpeg ffmpeg 0.5.2
    ffmpeg ffmpeg 0.5.3
    ffmpeg ffmpeg 0.5.4
    ffmpeg ffmpeg 0.5.4.5
    ffmpeg ffmpeg 0.5.4.6
    ffmpeg ffmpeg 0.5.5
    ffmpeg ffmpeg 0.6
    ffmpeg ffmpeg 0.6.1
    ffmpeg ffmpeg 0.6.2
    ffmpeg ffmpeg 0.6.3
    ffmpeg ffmpeg 0.7
    ffmpeg ffmpeg 0.7.1
    ffmpeg ffmpeg 0.7.2
    ffmpeg ffmpeg 0.7.3
    ffmpeg ffmpeg 0.7.4
    ffmpeg ffmpeg 0.7.5
    ffmpeg ffmpeg 0.7.6
    ffmpeg ffmpeg 0.7.7
    ffmpeg ffmpeg 0.7.8
    ffmpeg ffmpeg 0.7.9
    ffmpeg ffmpeg 0.7.11
    ffmpeg ffmpeg 0.7.12
    ffmpeg ffmpeg 0.8.0
    ffmpeg ffmpeg 0.8.1
    ffmpeg ffmpeg 0.8.2
    ffmpeg ffmpeg 0.8.5
    ffmpeg ffmpeg 0.8.5.3
    ffmpeg ffmpeg 0.8.5.4
    ffmpeg ffmpeg 0.8.6
    ffmpeg ffmpeg 0.8.7
    ffmpeg ffmpeg 0.8.8
    ffmpeg ffmpeg 0.8.10
    ffmpeg ffmpeg 0.8.11
    ffmpeg ffmpeg 0.9
    ffmpeg ffmpeg 0.9.1
    ffmpeg ffmpeg 0.10
    ffmpeg ffmpeg 0.10.3
    ffmpeg ffmpeg 0.10.4
    ffmpeg ffmpeg 0.11
    ffmpeg ffmpeg 1.0
    ffmpeg ffmpeg 1.1.1
    ffmpeg ffmpeg 1.1.2
    ffmpeg ffmpeg 1.1.3
    ffmpeg ffmpeg 1.1.4
    ffmpeg ffmpeg 1.2
    ffmpeg ffmpeg 1.2.1
    ffmpeg ffmpeg 2.0
    ffmpeg ffmpeg *
    debian debian linux 6.0
    ffmpeg ffmpeg 2.0