CVE-2012-2776
published 2012-09-10CVE-2012-2776: Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.12%
86.4th percentile
Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write."
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.10.4 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-11-12
CVE-2012-2772 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Debian
CVE-2012-2776: ffmpeg - Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3....
vendor_debian·2012·CVSS 10.0
CVE-2012-2776 [CRITICAL] CVE-2012-2776: ffmpeg - Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3....
Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-jg49-fg57-574h: Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3
ghsa_unreviewed·2022-05-14
CVE-2012-2776 [HIGH] GHSA-jg49-fg57-574h: Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3
Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write."
OSV
CVE-2012-2776: Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3
osv·2012-09-10·CVSS 10.0
CVE-2012-2776 [CRITICAL] CVE-2012-2776: Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3
Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=ba775a54bc2136ec5da85385a923b05ee6fab159http://libav.org/releases/libav-0.8.4.changeloghttp://secunia.com/advisories/50468http://secunia.com/advisories/51257http://www.mandriva.com/security/advisories?name=MDVSA-2013:079http://www.openwall.com/lists/oss-security/2012/08/31/3http://www.openwall.com/lists/oss-security/2012/09/02/4http://www.securityfocus.com/bid/55355http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=ba775a54bc2136ec5da85385a923b05ee6fab159http://libav.org/releases/libav-0.8.4.changeloghttp://secunia.com/advisories/50468http://secunia.com/advisories/51257http://www.mandriva.com/security/advisories?name=MDVSA-2013:079http://www.openwall.com/lists/oss-security/2012/08/31/3http://www.openwall.com/lists/oss-security/2012/09/02/4http://www.securityfocus.com/bid/55355
2012-09-10
Published