---
title: "CVE-2013-3670\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-3670?format=md
keywords: index, follow
---

# CVE-2013-3670

Publication date 10 June 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The rle\_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328
through 20130501 does not properly use the bytestream2 API, which allows
remote attackers to cause a denial of service (out-of-bounds array access
and application crash) via crafted RLE data. NOTE: the vendor has listed
this as an issue fixed in 1.2.1, but the issue is actually in new code that
was not shipped with the 1.2.1 release or any earlier release.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-3670?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ffmpeg | 13.10 saucy | Not in release |
| 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Ignored end of life |
| ffmpeg-extra | 13.10 saucy | Not in release |
| 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Ignored |
| libav | 13.10 saucy | Not affected |
| 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |
| libav-extra | 13.10 saucy | Not affected |
| 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

libav and ffmpeg codebases have diverged to the point of
not being able to track both using the same CVE numbers.
Marking this CVE as not-affected for libav.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3670)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-3670)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-3670)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-3670)

### Other references

* <http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=c1f2c4c3b49277d65b71ccdd3b6b2878f1b593eb>
* <https://www.cve.org/CVERecord?id=CVE-2013-3670>
