PublicDateAtUSN: 2013-03-09 Candidate: CVE-2013-2496 PublicDate: 2013-03-09 11:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2496 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=e398990eb87785e20e065cd3f14d1dbb69df4392 https://ubuntu.com/security/notices/USN-1790-1 Description: The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data. Ubuntu-Description: Notes: mdeslaur> ffmpeg-extra in multiverse needs to have matching version mdeslaur> libav-extra is built with tarball produced by libav package mdeslaur> ignoring releases near EoL. New version not available from mdeslaur> upstream. Bugs: https://bugs.launchpad.net/bugs/1163354 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: Patches_ffmpeg: upstream_ffmpeg: needs-triage hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: ignored oneiric_ffmpeg: DNE precise_ffmpeg: DNE quantal_ffmpeg: DNE raring_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: ignored oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE quantal_ffmpeg-extra: DNE raring_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream: http://git.libav.org/?p=libav.git;a=commit;h=327ff82bac3081d918dceb4931c77e25d0a1480d upstream: http://git.libav.org/?p=libav.git;a=commit;h=4160398e2a3e229e29dff03300aaf630e726a768 upstream_libav: released (0.8.6) hardy_libav: DNE lucid_libav: DNE oneiric_libav: ignored precise_libav: released (4:0.8.6-0ubuntu0.12.04.1) quantal_libav: released (6:0.8.6-0ubuntu0.12.10.1) raring_libav: not-affected (6:0.8.6-1ubuntu2) devel_libav: not-affected (6:0.8.6-1ubuntu2) Patches_libav-extra: upstream_libav-extra: released (0.8.6) hardy_libav-extra: DNE lucid_libav-extra: DNE oneiric_libav-extra: ignored precise_libav-extra: released (4:0.8.6ubuntu0.12.04.1) quantal_libav-extra: released (6:0.8.6ubuntu0.12.10.1) raring_libav-extra: not-affected (6:0.8.6ubuntu2) devel_libav-extra: not-affected (6:0.8.6ubuntu2)