Candidate: CVE-2012-6618 PublicDate: 2013-12-24 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6618 Description: The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate." Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_libav: upstream_libav: released (6:9.11-1) precise/esm_libav: DNE trusty_libav: ignored (out of standard support) trusty/esm_libav: DNE xenial_libav: DNE bionic_libav: DNE focal_libav: DNE groovy_libav: DNE hirsute_libav: DNE impish_libav: DNE jammy_libav: DNE devel_libav: DNE Patches_ffmpeg: upstream: https://git.videolan.org/?p=ffmpeg.git;a=commit;h=e74cd2f4706f71da5e9205003c1d8263b54ed3fb upstream_ffmpeg: released (7:2.4.1-1) precise/esm_ffmpeg: DNE trusty_ffmpeg: ignored (out of standard support) trusty/esm_ffmpeg: DNE xenial_ffmpeg: not-affected (7:2.8.6-1ubuntu2) bionic_ffmpeg: not-affected (7:3.4.2-2) focal_ffmpeg: not-affected (7:4.2.2-1ubuntu1) groovy_ffmpeg: not-affected hirsute_ffmpeg: not-affected impish_ffmpeg: not-affected (7:4.4-6ubuntu5) jammy_ffmpeg: not-affected (7:4.4.1-3ubuntu2) devel_ffmpeg: not-affected (7:4.4.1-3ubuntu2) Patches_qtwebengine-opensource-src: upstream_qtwebengine-opensource-src: needs-triage precise/esm_qtwebengine-opensource-src: DNE trusty_qtwebengine-opensource-src: ignored (out of standard support) trusty/esm_qtwebengine-opensource-src: DNE xenial_qtwebengine-opensource-src: DNE bionic_qtwebengine-opensource-src: needs-triage focal_qtwebengine-opensource-src: needs-triage groovy_qtwebengine-opensource-src: ignored (reached end-of-life) hirsute_qtwebengine-opensource-src: ignored (reached end-of-life) impish_qtwebengine-opensource-src: needs-triage jammy_qtwebengine-opensource-src: needs-triage devel_qtwebengine-opensource-src: needs-triage