Candidate: CVE-2013-2276 PublicDate: 2013-02-27 16:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2276 Description: The avcodec_decode_audio4 function in utils.c in libavcodec in FFmpeg before 1.1.3 does not verify the decoding state before proceeding with certain skip operations, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted audio data. Ubuntu-Description: Notes: mdeslaur> ffmpeg-extra in multiverse needs to have matching version mdeslaur> libav-extra is built with tarball produced by libav package jdstrand> avcodec_decode_audio4() does not exist in ffmpeg in Ubuntu 10.04 LTS or libav in Ubuntu 11.10 jdstrand> avcodec_decode_audio4() exists in Ubuntu 12.04 LTS and higher, but does not support skipping samples Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_ffmpeg: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8a6449167a6da8cb747cfe3502ae86ffaac2ed48 upstream_ffmpeg: needs-triage hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: not-affected (code-not-present) oneiric_ffmpeg: DNE precise_ffmpeg: DNE quantal_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: not-affected oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE quantal_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream_libav: needs-triage hardy_libav: DNE lucid_libav: DNE oneiric_libav: not-affected (code-not-present) precise_libav: not-affected (code-not-present) quantal_libav: not-affected (code-not-present) devel_libav: not-affected (code-not-present) Patches_libav-extra: upstream_libav-extra: needs-triage hardy_libav-extra: DNE lucid_libav-extra: DNE oneiric_libav-extra: not-affected precise_libav-extra: not-affected quantal_libav-extra: not-affected devel_libav-extra: not-affected