CVE-2013-0844
Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which triggers an out-of-bounds array access.
- Affected products
- Libav
- Ffmpeg
- ≤ 1.0.3, 0.3, 0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.4.0, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.4.6, 0.4.7, 0.4.8, 0.4.9, 0.5, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.4.5, 0.5.4.6, 0.6, 0.6.1, 0.6.2, 0.6.3, 0.7, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.7.8, 0.7.9, 0.7.11, 0.7.12, 0.8.0, 0.8.1
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 2.4% (83th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2013-12-07
CVE-2013-0844 at NVD
No indexed exploits for CVE-2013-0844 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-0844 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.