CVE-2012-6616Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
5.0MEDIUMNVD
EPSS
0.8%
top 26.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateMay 17

Description

The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDffmpeg/ffmpeg1.0.1+1
debiandebian/ffmpeg

🔴Vulnerability Details

2
GHSA
GHSA-fq8h-cfgh-9xpj: The mov_text_decode_frame function in libavcodec/movtextdec2022-05-17
OSV
CVE-2012-6616: The mov_text_decode_frame function in libavcodec/movtextdec2013-12-24

📋Vendor Advisories

1
Debian
CVE-2012-6616: ffmpeg - The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1...2012