CVE-2012-2803
published 2012-09-10CVE-2012-2803: Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.33%
87.4th percentile
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.10.4 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2013-01-28
CVE-2012-2783 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2013-01-28
CVE-2012-2783 FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that FFmpeg incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-2803: ffmpeg - Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12...
vendor_debian·2012·CVSS 10.0
CVE-2012-2803 [CRITICAL] CVE-2012-2803: ffmpeg - Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12...
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-v98x-wm9v-cm22: Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12
ghsa_unreviewed·2022-05-14
CVE-2012-2803 [HIGH] GHSA-v98x-wm9v-cm22: Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.
OSV
CVE-2012-2803: Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12
osv·2012-09-10·CVSS 10.0
CVE-2012-2803 [CRITICAL] CVE-2012-2803: Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=951cbea56fdc03ef96d07fbd7e5bed755d42ac8ahttp://libav.org/releases/libav-0.7.7.changeloghttp://libav.org/releases/libav-0.8.5.changeloghttp://secunia.com/advisories/50468http://www.openwall.com/lists/oss-security/2012/08/31/3http://www.openwall.com/lists/oss-security/2012/09/02/4http://www.securityfocus.com/bid/55355http://www.ubuntu.com/usn/USN-1705-1http://www.ubuntu.com/usn/USN-1706-1http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=951cbea56fdc03ef96d07fbd7e5bed755d42ac8ahttp://libav.org/releases/libav-0.7.7.changeloghttp://libav.org/releases/libav-0.8.5.changeloghttp://secunia.com/advisories/50468http://www.openwall.com/lists/oss-security/2012/08/31/3http://www.openwall.com/lists/oss-security/2012/09/02/4http://www.securityfocus.com/bid/55355http://www.ubuntu.com/usn/USN-1705-1http://www.ubuntu.com/usn/USN-1706-1
2012-09-10
Published