CVE-2012-2775: Critical severity Libav Libav vulnerability
Unspecified vulnerability in the readvarblockdata function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to a large order and an "out of array write in quantcof."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2775?
The severity of CVE-2012-2775 has not been specified, but it involves an out-of-bounds write potential which could lead to undefined behavior.
How do I fix CVE-2012-2775?
To fix CVE-2012-2775, you should update FFmpeg to version 0.11 or later, or Libav to versions 0.7.7 or 0.8.4 and later.
In which software is CVE-2012-2775 found?
CVE-2012-2775 is found in FFmpeg versions before 0.11 and Libav versions 0.7.x before 0.7.7 and 0.8.x before 0.8.4.
What are the potential impacts of CVE-2012-2775?
The potential impacts of CVE-2012-2775 include crashes, data corruption, and possibly remote code execution due to out-of-bounds writes.
Is there a working exploit for CVE-2012-2775?
As of the last reports, there is no publicly known exploit for CVE-2012-2775, but the vulnerability could be leveraged given its nature.