CVE-2012-0854 Information

Description

The dpcm_decode_frame function in libavcodec/dpcm.c in FFmpeg before 0.9.1 does not use the proper pointer after an audio API change which allows remote attackers to cause a denial of service (application crash) via unspecified vectors which triggers a heap-based buffer overflow.

Reference

http://ffmpeg.org/security.html http://git.videolan.org/?p=ffmpeg.git;a=commit;h=6d8e6fe9dbc365f50521cf0c4a5ffee97c970cb5 http://www.openwall.com/lists/oss-security/2012/02/01/11 http://www.openwall.com/lists/oss-security/2012/02/14/4

Share on: