Back to Database
Status published
Critical
CVE-2012-2787
Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg...
Vulnerability Description
Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "setup width/height."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2787
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2012/09/02/4
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=01bf2ad7351fdaa2e21b6bdf963d22d6ffccb920
- http://libav.org/releases/libav-0.8.4.changelog
- http://www.securityfocus.com/bid/55355
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:079
- http://www.openwall.com/lists/oss-security/2012/08/31/3
- http://ffmpeg.org/security.html
- http://secunia.com/advisories/50468
- http://secunia.com/advisories/51257
More from libav
View All →CVE-2020-18778
In Libav 12.3, there is a heap-based buffer over-read in...
Medium
6.5
CVE-2020-18776
In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr...
Medium
6.5
CVE-2020-18775
In Libav 12.3, there is a heap-based buffer over-read in...
Medium
6.5
CVE-2019-9720
A stack-based buffer overflow in the subtitle decoder in Libav...
Medium
6.5
CVE-2019-9719
A stack-based buffer overflow in the subtitle decoder in Libav...
High
8.8
Affected Vendor
libav
View all reports →Affected Software
libav, ffmpeg
Vulnerable Versions:
0.8, 0.8.1, 0.8.2, 0.8.3, 0, 0.3, 0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.4.0, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.4.6, 0.4.7, 0.4.8, 0.4.9, 0.5, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.4.5, 0.5.4.6, 0.6, 0.6.1, 0.6.2, 0.6.3, 0.7, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.7.8, 0.7.9, 0.7.11, 0.7.12, 0.8.0, 0.8.5, 0.8.5.3, 0.8.5.4, 0.8.6, 0.8.7, 0.8.8, 0.8.10, 0.8.11, 0.9, 0.9.1, 0.10, 0.10.3
Timeline
Official Publish:
September 10th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.