---
title: "CVE-2013-0894\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-0894?format=md
keywords: index, follow
---

# CVE-2013-0894

Publication date 23 February 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer overflow in the vorbis\_parse\_setup\_hdr\_floors function in the Vorbis
decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in
Google Chrome before 25.0.1364.97 on Windows and Linux and before
25.0.1364.99 on Mac OS X and other products, allows remote attackers to
cause a denial of service (divide-by-zero error or out-of-bounds array
access) or possibly have unspecified other impact via vectors involving a
zero value for a bark map size.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-0894?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 13.04 raring | Fixed 25.0.1364.160-0ubuntu1 |
| 12.10 quantal | Fixed 25.0.1364.160-0ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 25.0.1364.160-0ubuntu0.12.04.1 |
| 11.10 oneiric | Fixed 25.0.1364.160-0ubuntu0.11.10.1 |
| 10.04 LTS lucid | Fixed 25.0.1364.160-0ubuntu0.10.04.1 |
| 8.04 LTS hardy | Not in release |
| ffmpeg | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 10.04 LTS lucid | Ignored |
| 8.04 LTS hardy | Ignored end of life |
| ffmpeg-extra | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 10.04 LTS lucid | Ignored |
| 8.04 LTS hardy | Not in release |
| libav | 13.04 raring | Not affected |
| 12.10 quantal | Fixed 6:0.8.6-0ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 4:0.8.6-0ubuntu0.12.04.1 |
| 11.10 oneiric | Ignored |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| libav-extra | 13.04 raring | Not affected |
| 12.10 quantal | Fixed 6:0.8.6ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 4:0.8.6ubuntu0.12.04.1 |
| 11.10 oneiric | Ignored |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2013-0894?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

ignoring releases near EoL. New version not available from
upstream.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libav | * Upstream:   <http://git.libav.org/?p=libav.git;a=commit;h=e050af9a809bd4e223c89e280ebd94da0e1034b5> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0894)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-0894)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-0894)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-0894)

### Related Ubuntu Security Notices (USN)

+ [USN-1790-1](https://usn.ubuntu.com/USN-1790-1)
+ Libav vulnerabilities
+ 4 April 2013

### Other references

* <http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-0894>
