Description
The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Shorten file, related to an "invalid free".
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1479-1
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/02/14/4
Patch x_refsource_confirm
http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=204cb29b3c84a74cbcd059d353c70c8bdc567d98
Vendor Advisory x_refsource_confirm
http://ffmpeg.org/
Vendor Advisory x_refsource_confirm
http://libav.org/
Various Sources x_refsource_confirm
http://git.libav.org/?p=libav.git%3Ba=commitdiff%3Bh=204cb29b3c84a74cbcd059d353c70c8bdc567d98
Scores
EPSS
0.0279
EPSS Percentile
86.3%
Details
CWE
CWE-399
Status
published
Products (32)
ffmpeg/ffmpeg
0.7.1
ffmpeg/ffmpeg
0.7.2
ffmpeg/ffmpeg
0.7.6
ffmpeg/ffmpeg
0.7.7
ffmpeg/ffmpeg
0.7.8
ffmpeg/ffmpeg
0.7.9
ffmpeg/ffmpeg
0.7.11
ffmpeg/ffmpeg
0.8.5
ffmpeg/ffmpeg
0.8.6
ffmpeg/ffmpeg
0.8.7
... and 22 more
Published
Aug 20, 2012
Tracked Since
Feb 18, 2026