CVE-2012-6618
published 2013-12-24CVE-2012-6618: The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause…
PriorityP410low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
1.58%
73.0th percentile
The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 1.0.1 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c3mp-24r8-cfj3: The av_probe_input_buffer function in libavformat/utils
ghsa_unreviewed·2022-05-17
CVE-2012-6618 [LOW] CWE-119 GHSA-c3mp-24r8-cfj3: The av_probe_input_buffer function in libavformat/utils
The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate."
OSV
CVE-2012-6618: The av_probe_input_buffer function in libavformat/utils
osv·2013-12-24·CVSS 2.6
CVE-2012-6618 [LOW] CVE-2012-6618: The av_probe_input_buffer function in libavformat/utils
The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate."
Debian
CVE-2012-6618: ffmpeg - The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2...
vendor_debian·2012·CVSS 2.6
CVE-2012-6618 [LOW] CVE-2012-6618: ffmpeg - The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2...
The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
No detection rules found.
No writeups or analysis indexed.
http://article.gmane.org/gmane.comp.video.ffmpeg.user/42233http://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v9.11http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=e74cd2f4706f71da5e9205003c1d8263b54ed3fbhttp://secunia.com/advisories/51964http://www.ffmpeg.org/security.htmlhttps://trac.ffmpeg.org/ticket/1991http://article.gmane.org/gmane.comp.video.ffmpeg.user/42233http://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v9.11http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=e74cd2f4706f71da5e9205003c1d8263b54ed3fbhttp://secunia.com/advisories/51964http://www.ffmpeg.org/security.htmlhttps://trac.ffmpeg.org/ticket/1991
2013-12-24
Published