CVE-2012-0947
published 2012-08-20CVE-2012-0947: Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.69%
90.8th percentile
Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of the block size.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
| libav | libav | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2012-06-18·CVSS 6.8
CVE-2011-3929 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash or run programs as your login if it
opened a specially crafted file.
Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly
handled certain malformed DV files. If a user were tricked into opening a
crafted DV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking the program. (CVE-2011-3929, CVE-2011-3936)
Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly
handled certain malformed NSV files. If a user were tricked into opening a
crafted NSV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking t
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-06-18·CVSS 6.8
CVE-2011-3929 [MEDIUM] Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it
opened a specially crafted file.
Mateusz Jurczyk and Gynvael Coldwind discovered that Libav incorrectly
handled certain malformed DV files. If a user were tricked into opening a
crafted DV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking the program. This issue only affected Ubuntu 11.10.
(CVE-2011-3929, CVE-2011-3936)
Mateusz Jurczyk and Gynvael Coldwind discovered that Libav incorrectly
handled certain malformed NSV files. If a user were tricked into opening a
crafted NSV file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with th
Debian
CVE-2012-0947: ffmpeg - Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vq...
vendor_debian·2012·CVSS 6.8
CVE-2012-0947 [MEDIUM] CVE-2012-0947: ffmpeg - Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vq...
Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of the block size.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-mrcx-gg4f-hxqf: Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo
ghsa_unreviewed·2022-05-17
CVE-2012-0947 [MEDIUM] CWE-119 GHSA-mrcx-gg4f-hxqf: Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo
Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of the block size.
OSV
CVE-2012-0947: Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo
osv·2012-08-20·CVSS 6.8
CVE-2012-0947 [MEDIUM] CVE-2012-0947: Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo
Heap-based buffer overflow in the vqa_decode_chunk function in the VQA codec (vqavideo.c) in libavcodec in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VQA media file in which the image size is not a multiple of the block size.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.libav.org/?p=libav.git%3Ba=commit%3Bh=58b2e0f0f2fc96c1158e04f8aba95cbe6157a1a3http://libav.org/http://secunia.com/advisories/49089http://www.debian.org/security/2012/dsa-2471http://www.openwall.com/lists/oss-security/2012/05/03/4http://www.securityfocus.com/bid/53389http://www.ubuntu.com/usn/USN-1479-1https://bugs.launchpad.net/ubuntu/+source/libav/+bug/980963http://git.libav.org/?p=libav.git%3Ba=commit%3Bh=58b2e0f0f2fc96c1158e04f8aba95cbe6157a1a3http://libav.org/http://secunia.com/advisories/49089http://www.debian.org/security/2012/dsa-2471http://www.openwall.com/lists/oss-security/2012/05/03/4http://www.securityfocus.com/bid/53389http://www.ubuntu.com/usn/USN-1479-1https://bugs.launchpad.net/ubuntu/+source/libav/+bug/980963
2012-08-20
Published