CVE-2012-0850: Buffer Overflow
The sbrqmfsynthesis function in libavcodec/aacsbr.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted mpg file that triggers memory corruption involving the voff variable, probably a buffer underflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0850?
CVE-2012-0850 has a severity rating that indicates a denial of service vulnerability which can cause application crashes.
How do I fix CVE-2012-0850?
To fix CVE-2012-0850, upgrade to FFmpeg version 0.9.1 or later.
What systems are affected by CVE-2012-0850?
CVE-2012-0850 affects multiple versions of FFmpeg prior to 0.9.1, including all versions from 0.3 to 0.8.11.
What is the impact of exploiting CVE-2012-0850?
Exploiting CVE-2012-0850 can lead to memory corruption which may result in application crashes and denial of service.
Is there a workaround for CVE-2012-0850?
There are no known effective workarounds for CVE-2012-0850, so it is recommended to upgrade to a patched version.