Candidate: CVE-2013-3670 PublicDate: 2013-06-10 03:19:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3670 http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=c1f2c4c3b49277d65b71ccdd3b6b2878f1b593eb Description: The rle_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328 through 20130501 does not properly use the bytestream2 API, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted RLE data. NOTE: the vendor has listed this as an issue fixed in 1.2.1, but the issue is actually in new code that was not shipped with the 1.2.1 release or any earlier release. Ubuntu-Description: Notes: mdeslaur> libav and ffmpeg codebases have diverged to the point of mdeslaur> not being able to track both using the same CVE numbers. mdeslaur> Marking this CVE as not-affected for libav. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ffmpeg: upstream_ffmpeg: needs-triage lucid_ffmpeg: ignored (reached end-of-life) precise_ffmpeg: DNE quantal_ffmpeg: DNE raring_ffmpeg: DNE saucy_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage lucid_ffmpeg-extra: ignored precise_ffmpeg-extra: DNE quantal_ffmpeg-extra: DNE raring_ffmpeg-extra: DNE saucy_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream_libav: needs-triage lucid_libav: DNE precise_libav: not-affected quantal_libav: not-affected raring_libav: not-affected saucy_libav: not-affected devel_libav: not-affected Patches_libav-extra: upstream_libav-extra: needs-triage lucid_libav-extra: DNE precise_libav-extra: not-affected quantal_libav-extra: not-affected raring_libav-extra: not-affected saucy_libav-extra: not-affected devel_libav-extra: not-affected