|
|
Subscribe / Log in / New account

libav: multiple vulnerabilities

Package(s):libav ffmpeg CVE #(s):CVE-2012-2783 CVE-2012-2791 CVE-2012-2797 CVE-2012-2803 CVE-2012-2804
Created:January 28, 2013 Updated:May 9, 2013
Description: From the CVE entries:

Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to "freeing the returned frame." (CVE-2012-2783)

Multiple unspecified vulnerabilities in the (1) decode_band_hdr function in indeo4.c and (2) ff_ivi_decode_blocks function in ivi_common.c in libavcodec/ in FFmpeg before 0.11 have unknown impact and attack vectors, related to the "transform size." (CVE-2012-2791)

Unspecified vulnerability in the decode_frame_mp3on4 function in libavcodec/mpegaudiodec.c in FFmpeg before 0.11 has unknown impact and attack vectors related to a calculation that prevents a frame from being "large enough." (CVE-2012-2797)

Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to resetting the data size value. (CVE-2012-2803)

Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to "reallocation code" and the luma height and width. (CVE-2012-2804)

Alerts:
Gentoo 201406-28 libav 2014-06-26
Gentoo 201310-12 ffmpeg 2013-10-25
Mageia MGASA-2013-0136 ffmpeg 2013-05-09
Debian DSA-2624-1 ffmpeg 2013-02-16
Ubuntu USN-1706-1 ffmpeg 2013-01-28
Ubuntu USN-1705-1 libav 2013-01-28

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds