VDB
CVE-2013-0865
CVE-2013-0865
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Video file, which triggers an out-of-bounds write.
EPSS 0.85% · 75.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
0.85%
75.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ffmpeg | ffmpeg | 1.0, 0, 0.3 |
| n/a | n/a | n/a |
Exploit Intelligence
Timeline
- Nov 23, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=08e2c7a45f82b897a285548c257972eb1ad352c5 url
- DSA-2855 vendor-advisory
- http://www.ffmpeg.org/security.html url
- GLSA-201603-06 vendor-advisory
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=f3d16706060ab6ae6dc78f15359fab3fd87c9495 url
- https://nvd.nist.gov/vuln/detail/CVE-2013-0865 advisory
- http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=08e2c7a45f82b897a285548c257972eb1ad352c5 url
- http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=f3d16706060ab6ae6dc78f15359fab3fd87c9495 url