CVE-2012-0856: Buffer Overflow
Heap-based buffer overflow in the MPVframestart function in libavcodec/mpegvideo.c in FFmpeg before 0.9.1, when the lowres option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted H263 media file. NOTE: this vulnerability exists because of a regression error.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0856?
CVE-2012-0856 has a severity level that may lead to denial of service due to a heap-based buffer overflow.
How do I fix CVE-2012-0856?
To mitigate CVE-2012-0856, it is recommended to upgrade to FFmpeg version 0.9.1 or later.
What causes the vulnerability in CVE-2012-0856?
CVE-2012-0856 is caused by a heap-based buffer overflow in the MPV_frame_start function when the lowres option is enabled.
Which versions of FFmpeg are affected by CVE-2012-0856?
FFmpeg versions prior to 0.9.1, including versions 0.3 through 0.8.11, are affected by CVE-2012-0856.
What type of attack can exploit CVE-2012-0856?
CVE-2012-0856 can be exploited by remote attackers using crafted H263 media files to crash the application.