CVE-2012-0947: Buffer Overflow
Heap-based buffer overflow in the vqadecodechunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of the block size.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0947?
CVE-2012-0947 has a severity rating that could lead to denial of service and the potential for remote code execution.
How do I fix CVE-2012-0947?
To address CVE-2012-0947, upgrade to Libav versions 0.5.9, 0.6.6, 0.7.6, or 0.8.2 or later.
What versions of Libav are affected by CVE-2012-0947?
CVE-2012-0947 affects Libav versions 0.5.x before 0.5.9, 0.6.x before 0.6.6, and 0.7.x before 0.7.6, and 0.8.x before 0.8.2.
What type of vulnerability is CVE-2012-0947?
CVE-2012-0947 is a heap-based buffer overflow vulnerability in the vqa_decode_chunk function.
Can CVE-2012-0947 be exploited remotely?
Yes, CVE-2012-0947 can be exploited by remote attackers to cause denial of service and potentially execute arbitrary code.