CVE-2012-2801
published 2012-09-10CVE-2012-2801: Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.97%
85.8th percentile
Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.10.4 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8gr4-47p2-7q2w: Unspecified vulnerability in libavcodec/avs
ghsa_unreviewed·2022-05-14
CVE-2012-2801 [HIGH] GHSA-8gr4-47p2-7q2w: Unspecified vulnerability in libavcodec/avs
Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."
OSV
CVE-2012-2801: Unspecified vulnerability in libavcodec/avs
osv·2012-09-10·CVSS 10.0
CVE-2012-2801 [CRITICAL] CVE-2012-2801: Unspecified vulnerability in libavcodec/avs
Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2013-01-28
CVE-2012-2783 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-12-19
CVE-2012-2772 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2012-12-19
CVE-2012-2777 FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that FFmpeg incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-11-12
CVE-2012-2772 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Debian
CVE-2012-2801: ffmpeg - Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0...
vendor_debian·2012·CVSS 10.0
CVE-2012-2801 [CRITICAL] CVE-2012-2801: ffmpeg - Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0...
Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=1df49142bab1b7bccd11392aa9e819e297d21a6ehttp://libav.org/releases/libav-0.7.7.changeloghttp://libav.org/releases/libav-0.8.4.changeloghttp://libav.org/releases/libav-0.8.5.changeloghttp://secunia.com/advisories/50468http://secunia.com/advisories/51257http://www.mandriva.com/security/advisories?name=MDVSA-2013:079http://www.openwall.com/lists/oss-security/2012/08/31/3http://www.openwall.com/lists/oss-security/2012/09/02/4http://www.securityfocus.com/bid/55355http://www.ubuntu.com/usn/USN-1705-1http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=1df49142bab1b7bccd11392aa9e819e297d21a6ehttp://libav.org/releases/libav-0.7.7.changeloghttp://libav.org/releases/libav-0.8.4.changeloghttp://libav.org/releases/libav-0.8.5.changeloghttp://secunia.com/advisories/50468http://secunia.com/advisories/51257http://www.mandriva.com/security/advisories?name=MDVSA-2013:079http://www.openwall.com/lists/oss-security/2012/08/31/3http://www.openwall.com/lists/oss-security/2012/09/02/4http://www.securityfocus.com/bid/55355http://www.ubuntu.com/usn/USN-1705-1
2012-09-10
Published