CVE-2012-0847: Buffer Overflow
Published Aug 20, 2012
·Updated
Heap-based buffer overflow in the avfilterfiltersamples function in libavfilter/avfilter.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted media file.
Affected Software
14 affected components
FFmpeg FFmpeg<=0.9
FFmpeg FFmpeg=0.7.1
FFmpeg FFmpeg=0.7.2
FFmpeg FFmpeg=0.7.7
FFmpeg FFmpeg=0.7.8
FFmpeg FFmpeg=0.7.9
FFmpeg FFmpeg=0.7.11
FFmpeg FFmpeg=0.7.12
FFmpeg FFmpeg=0.8.5
FFmpeg FFmpeg=0.8.6
FFmpeg FFmpeg=0.8.7
FFmpeg FFmpeg=0.8.8
FFmpeg FFmpeg=0.8.10
FFmpeg FFmpeg=0.8.11
Event History
Aug 20, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0847?
CVE-2012-0847 is classified as a high severity vulnerability due to its potential to cause a denial of service by crashing the application.
2
How do I fix CVE-2012-0847?
To fix CVE-2012-0847, update FFmpeg to version 0.9.1 or later, as the vulnerability has been patched in these versions.
3
Which versions of FFmpeg are affected by CVE-2012-0847?
CVE-2012-0847 affects FFmpeg versions 0.7.1 through 0.9 inclusive.
4
What type of vulnerability is CVE-2012-0847?
CVE-2012-0847 is a heap-based buffer overflow vulnerability found in the avfilter_filter_samples function.
5
Can CVE-2012-0847 be exploited remotely?
Yes, CVE-2012-0847 can be exploited remotely through crafted media files.