First published: Mon Aug 20 2012(Updated: )
The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=0.9 | |
FFmpeg | =0.7.1 | |
FFmpeg | =0.7.2 | |
FFmpeg | =0.7.7 | |
FFmpeg | =0.7.8 | |
FFmpeg | =0.7.9 | |
FFmpeg | =0.7.11 | |
FFmpeg | =0.7.12 | |
FFmpeg | =0.8.5 | |
FFmpeg | =0.8.6 | |
FFmpeg | =0.8.7 | |
FFmpeg | =0.8.8 | |
FFmpeg | =0.8.10 | |
FFmpeg | =0.8.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0859 has a high severity level due to its potential for denial of service and arbitrary code execution.
To fix CVE-2012-0859, upgrade to FFmpeg version 0.9.1 or later.
CVE-2012-0859 is caused by the render_line function in the vorbis codec improperly handling crafted Vorbis files.
CVE-2012-0859 affects all FFmpeg versions prior to 0.9.1 and specific older versions like 0.7.1, 0.7.2, 0.7.7, 0.7.8, 0.7.9, 0.7.11, 0.7.12, and multiple from the 0.8 series.
Using older versions of FFmpeg affected by CVE-2012-0859 is unsafe as they could lead to application crashes and security risks.