{
  "modified": "2025-08-09T19:01:28Z",
  "published": "2013-03-09T11:55:01Z",
  "id": "CVE-2013-2495",
  "details": "The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a video codec, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) or possibly have unspecified other impact via a crafted header.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://www.ubuntu.com/usn/USN-1790-1"
    },
    {
      "type": "WEB",
      "url": "http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=3dbc0ff9c3e6f6e0d08ea3d42cb33761bae084ba"
    }
  ]
}
