CVE-2013-0858

critical

Description

The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.

References

http://www.ffmpeg.org/security.html

http://www.debian.org/security/2013/dsa-2793

http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=2502914c5f8eb77659d7c0868396862557a63245

http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=13451f5520ce6b0afde861b2285dda659f8d4fb4

Details

Source: Mitre, NVD

Published: 2013-12-07

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical