CVE-2012-0851
published 2012-08-20CVE-2012-0851: The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.23%
87.0th percentile
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.9 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2012-06-18·CVSS 6.8
CVE-2011-3929 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash or run programs as your login if it
opened a specially crafted file.
Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly
handled certain malformed DV files. If a user were tricked into opening a
crafted DV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking the program. (CVE-2011-3929, CVE-2011-3936)
Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly
handled certain malformed NSV files. If a user were tricked into opening a
crafted NSV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking t
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-06-18·CVSS 6.8
CVE-2011-3929 [MEDIUM] Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it
opened a specially crafted file.
Mateusz Jurczyk and Gynvael Coldwind discovered that Libav incorrectly
handled certain malformed DV files. If a user were tricked into opening a
crafted DV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking the program. This issue only affected Ubuntu 11.10.
(CVE-2011-3929, CVE-2011-3936)
Mateusz Jurczyk and Gynvael Coldwind discovered that Libav incorrectly
handled certain malformed NSV files. If a user were tricked into opening a
crafted NSV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with th
Debian
CVE-2012-0851: ffmpeg - The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmp...
vendor_debian·2012·CVSS 6.8
CVE-2012-0851 [MEDIUM] CVE-2012-0851: ffmpeg - The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmp...
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-mh6c-cqhm-4rxx: The ff_h264_decode_seq_parameter_set function in h264_ps
ghsa_unreviewed·2022-05-17
CVE-2012-0851 [MEDIUM] CWE-119 GHSA-mh6c-cqhm-4rxx: The ff_h264_decode_seq_parameter_set function in h264_ps
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.
OSV
CVE-2012-0851: The ff_h264_decode_seq_parameter_set function in h264_ps
osv·2012-08-20·CVSS 6.8
CVE-2012-0851 [MEDIUM] CVE-2012-0851: The ff_h264_decode_seq_parameter_set function in h264_ps
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.org/security.htmlhttp://ffmpeg.org/trac/ffmpeg/ticket/758http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=7fff64e00d886fde11d61958888c82b461cf99b9http://libav.org/http://www.debian.org/security/2012/dsa-2494http://www.mandriva.com/security/advisories?name=MDVSA-2013:079http://www.openwall.com/lists/oss-security/2012/02/14/4http://www.ubuntu.com/usn/USN-1479-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78933http://ffmpeg.org/security.htmlhttp://ffmpeg.org/trac/ffmpeg/ticket/758http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=7fff64e00d886fde11d61958888c82b461cf99b9http://libav.org/http://www.debian.org/security/2012/dsa-2494http://www.mandriva.com/security/advisories?name=MDVSA-2013:079http://www.openwall.com/lists/oss-security/2012/02/14/4http://www.ubuntu.com/usn/USN-1479-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78933
2012-08-20
Published