PT-2012-4274 · FFmpeg+1 · Ffmpeg+1

Published

2012-09-10

·

Updated

2018-10-30

·

CVE-2012-2803

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 0.11 Libav versions 0.7.x prior to 0.7.7 Libav versions 0.8.x prior to 0.8.5
Description A double free vulnerability exists in the mpeg decode frame function, located in libavcodec/mpeg12.c, which has unknown impact and attack vectors. This issue is related to resetting the data size value.
Recommendations For FFmpeg versions prior to 0.11, update to version 0.11 or later. For Libav versions 0.7.x prior to 0.7.7, update to version 0.7.7 or later. For Libav versions 0.8.x prior to 0.8.5, update to version 0.8.5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2803
DSA-2624-1

Affected Products

Ffmpeg
Libav