PublicDateAtUSN: 2013-03-09 Candidate: CVE-2013-2495 PublicDate: 2013-03-09 11:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2495 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=3dbc0ff9c3e6f6e0d08ea3d42cb33761bae084ba https://ubuntu.com/security/notices/USN-1790-1 Description: The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a video codec, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) or possibly have unspecified other impact via a crafted header. Ubuntu-Description: Notes: mdeslaur> ffmpeg-extra in multiverse needs to have matching version mdeslaur> libav-extra is built with tarball produced by libav package mdeslaur> ignoring releases near EoL. New version not available from mdeslaur> upstream. Bugs: https://bugs.launchpad.net/bugs/1163354 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: Patches_ffmpeg: upstream_ffmpeg: needs-triage hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: ignored oneiric_ffmpeg: DNE precise_ffmpeg: DNE quantal_ffmpeg: DNE raring_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: ignored oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE quantal_ffmpeg-extra: DNE raring_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream: http://git.libav.org/?p=libav.git;a=commit;h=36aad4f1cc707feb15f071260a99f239b6623a59 upstream_libav: released (0.8.6) hardy_libav: DNE lucid_libav: DNE oneiric_libav: ignored precise_libav: released (4:0.8.6-0ubuntu0.12.04.1) quantal_libav: released (6:0.8.6-0ubuntu0.12.10.1) raring_libav: not-affected (6:0.8.6-1ubuntu2) devel_libav: not-affected (6:0.8.6-1ubuntu2) Patches_libav-extra: upstream_libav-extra: released (0.8.6) hardy_libav-extra: DNE lucid_libav-extra: DNE oneiric_libav-extra: ignored precise_libav-extra: released (4:0.8.6ubuntu0.12.04.1) quantal_libav-extra: released (6:0.8.6ubuntu0.12.10.1) raring_libav-extra: not-affected (6:0.8.6ubuntu2) devel_libav-extra: not-affected (6:0.8.6ubuntu2)