CVE-2012-0851: Buffer Overflow
The ffh264decodeseqparameterset function in h264ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chromaformatidc value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0851?
CVE-2012-0851 has a severity rating that allows for remote attackers to potentially cause a denial of service and execute arbitrary code.
How do I fix CVE-2012-0851?
To fix CVE-2012-0851, upgrade to FFmpeg version 0.9.1 or higher, or Libav version 0.5.9, 0.6.6, 0.7.6, 0.8.3, or higher.
Which versions of FFmpeg are affected by CVE-2012-0851?
Affected versions of FFmpeg include all versions prior to 0.9.1, as well as specific older versions including 0.7.1, 0.7.2, 0.7.7, 0.7.8, etc.
Which versions of Libav are affected by CVE-2012-0851?
CVE-2012-0851 affects Libav versions prior to 0.5.9, as well as specific versions such as 0.5, 0.5.1, 0.5.2, up to 0.8.2.
What types of attacks can CVE-2012-0851 facilitate?
CVE-2012-0851 can facilitate remote denial of service attacks and may allow for arbitrary code execution.