CVE-2012-0858

FFmpeg <0.7.12 & Libav <0.5.9-0.8.11 - DoS/Code Injection

Title source: llm
STIX 2.1

Description

The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Shorten file, related to an "invalid free".

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1479-1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/02/14/4
Vendor Advisory x_refsource_confirm
http://ffmpeg.org/
Vendor Advisory x_refsource_confirm
http://libav.org/

Scores

EPSS 0.0279
EPSS Percentile 86.3%

Details

CWE
CWE-399
Status published
Products (32)
ffmpeg/ffmpeg 0.7.1
ffmpeg/ffmpeg 0.7.2
ffmpeg/ffmpeg 0.7.6
ffmpeg/ffmpeg 0.7.7
ffmpeg/ffmpeg 0.7.8
ffmpeg/ffmpeg 0.7.9
ffmpeg/ffmpeg 0.7.11
ffmpeg/ffmpeg 0.8.5
ffmpeg/ffmpeg 0.8.6
ffmpeg/ffmpeg 0.8.7
... and 22 more
Published Aug 20, 2012
Tracked Since Feb 18, 2026