CVE-2012-0853

FFmpeg 0.7.x < 0.7.12 and 0.8.x < 0.8.11 - Denial of Service via Atrac3 Codec Component Count

Title source: llm
STIX 2.1

Description

The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (infinite loop and crash) and possibly execute arbitrary code via a large component count in an Atrac 3 file.

References (7)

Core 7

Scores

EPSS 0.0120
EPSS Percentile 79.1%

Details

CWE
CWE-20
Status published
Products (37)
ffmpeg/ffmpeg 0.7
ffmpeg/ffmpeg 0.7.1
ffmpeg/ffmpeg 0.7.2
ffmpeg/ffmpeg 0.7.3
ffmpeg/ffmpeg 0.7.6
ffmpeg/ffmpeg 0.7.7
ffmpeg/ffmpeg 0.7.8
ffmpeg/ffmpeg 0.7.9
ffmpeg/ffmpeg 0.7.11
ffmpeg/ffmpeg 0.8.0
... and 27 more
Published Aug 20, 2012
Tracked Since Feb 18, 2026