First published: Mon Aug 20 2012(Updated: )
Heap-based buffer overflow in the ws_snd_decode_frame function in libavcodec/ws-snd1.c in FFmpeg 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted media file, related to an incorrect calculation, aka "wrong samples count."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =0.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0848 is considered a denial of service vulnerability due to a heap-based buffer overflow.
To fix CVE-2012-0848, upgrade to a patched version of FFmpeg that addresses this vulnerability.
CVE-2012-0848 affects FFmpeg version 0.9.1.
CVE-2012-0848 allows remote attackers to execute a denial of service attack by crashing the application.
The vulnerability in CVE-2012-0848 exists in the ws_snd_decode_frame function of libavcodec/ws-snd1.c.