CVE-2013-0894

FFmpeg <1.1.3 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.

Scores

EPSS 0.0047
EPSS Percentile 64.6%

Details

CWE
CWE-120
Status published
Products (6)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
ffmpeg/ffmpeg < 1.1.3
google/chrome < 25.0.1364.99
opensuse/opensuse 12.1
opensuse/opensuse 12.2
Published Feb 23, 2013
Tracked Since Feb 18, 2026