CVE-2013-0864

critical
Published 2013-11-23 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-0864

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
ffmpegffmpeg{"endIncluding":"1.1.1"}
ffmpegffmpeg0.3
ffmpegffmpeg0.3.1
ffmpegffmpeg0.3.2
ffmpegffmpeg0.3.3
ffmpegffmpeg0.3.4
ffmpegffmpeg0.4.0
ffmpegffmpeg0.4.2
ffmpegffmpeg0.4.3
ffmpegffmpeg0.4.4
ffmpegffmpeg0.4.5
ffmpegffmpeg0.4.6
ffmpegffmpeg0.4.7
ffmpegffmpeg0.4.8
ffmpegffmpeg0.4.9
ffmpegffmpeg0.5
ffmpegffmpeg0.5.1
ffmpegffmpeg0.5.2
ffmpegffmpeg0.5.3
ffmpegffmpeg0.5.4
ffmpegffmpeg0.5.4.5
ffmpegffmpeg0.5.4.6
ffmpegffmpeg0.6
ffmpegffmpeg0.6.1
ffmpegffmpeg0.6.2
ffmpegffmpeg0.6.3
ffmpegffmpeg0.7
ffmpegffmpeg0.7.1
ffmpegffmpeg0.7.2
ffmpegffmpeg0.7.3
ffmpegffmpeg0.7.4
ffmpegffmpeg0.7.5
ffmpegffmpeg0.7.6
ffmpegffmpeg0.7.7
ffmpegffmpeg0.7.8
ffmpegffmpeg0.7.9
ffmpegffmpeg0.7.11
ffmpegffmpeg0.7.12
ffmpegffmpeg0.8.0
ffmpegffmpeg0.8.1
ffmpegffmpeg0.8.2
ffmpegffmpeg0.8.5
ffmpegffmpeg0.8.5.3
ffmpegffmpeg0.8.5.4
ffmpegffmpeg0.8.6
ffmpegffmpeg0.8.7
ffmpegffmpeg0.8.8
ffmpegffmpeg0.8.10
ffmpegffmpeg0.8.11
ffmpegffmpeg0.9
ffmpegffmpeg0.9.1
ffmpegffmpeg0.10
ffmpegffmpeg0.10.3
ffmpegffmpeg0.10.4
ffmpegffmpeg0.11
ffmpegffmpeg1.0

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.