CVE-2012-2797: Critical severity FFmpeg FFmpeg vulnerability
Unspecified vulnerability in the decodeframemp3on4 function in libavcodec/mpegaudiodec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors related to a calculation that prevents a frame from being "large enough."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2797?
The severity of CVE-2012-2797 is currently unknown due to the lack of details about its impact and attack vectors.
What software versions are affected by CVE-2012-2797?
CVE-2012-2797 affects FFmpeg versions before 0.11 and Libav versions before 0.8.5.
How do I fix CVE-2012-2797?
To fix CVE-2012-2797, users should update to the latest versions of FFmpeg or Libav that are not vulnerable.
What is the cause of CVE-2012-2797?
CVE-2012-2797 is caused by an unspecified vulnerability in the decode_frame_mp3on4 function related to frame size calculation.
Are there any workarounds for CVE-2012-2797?
As of now, there are no specific workarounds recommended for CVE-2012-2797 other than updating to secure software versions.