First published: Mon Aug 20 2012(Updated: )
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=0.9 | |
FFmpeg | =0.7.1 | |
FFmpeg | =0.7.2 | |
FFmpeg | =0.7.7 | |
FFmpeg | =0.7.8 | |
FFmpeg | =0.7.9 | |
FFmpeg | =0.7.11 | |
FFmpeg | =0.7.12 | |
FFmpeg | =0.8.5 | |
FFmpeg | =0.8.6 | |
FFmpeg | =0.8.7 | |
FFmpeg | =0.8.8 | |
FFmpeg | =0.8.10 | |
FFmpeg | =0.8.11 | |
Libav | =0.5 | |
Libav | =0.5.1 | |
Libav | =0.5.2 | |
Libav | =0.5.3 | |
Libav | =0.5.4 | |
Libav | =0.5.5 | |
Libav | =0.5.6 | |
Libav | =0.5.7 | |
Libav | =0.6 | |
Libav | =0.6.1 | |
Libav | =0.6.2 | |
Libav | =0.6.3 | |
Libav | =0.6.4 | |
Libav | =0.6.5 | |
Libav | =0.7 | |
Libav | =0.7.1 | |
Libav | =0.7.2 | |
Libav | =0.7.3 | |
Libav | =0.7.4 | |
Libav | =0.7.5 | |
Libav | =0.8 | |
Libav | =0.8-beta2 | |
Libav | =0.8.1 | |
Libav | =0.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0851 has a severity rating that allows for remote attackers to potentially cause a denial of service and execute arbitrary code.
To fix CVE-2012-0851, upgrade to FFmpeg version 0.9.1 or higher, or Libav version 0.5.9, 0.6.6, 0.7.6, 0.8.3, or higher.
Affected versions of FFmpeg include all versions prior to 0.9.1, as well as specific older versions including 0.7.1, 0.7.2, 0.7.7, 0.7.8, etc.
CVE-2012-0851 affects Libav versions prior to 0.5.9, as well as specific versions such as 0.5, 0.5.1, 0.5.2, up to 0.8.2.
CVE-2012-0851 can facilitate remote denial of service attacks and may allow for arbitrary code execution.