Candidate: CVE-2012-0854 PublicDate: 2012-08-20 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0854 http://www.openwall.com/lists/oss-security/2012/02/14/4 Description: The dpcm_decode_frame function in libavcodec/dpcm.c in FFmpeg before 0.9.1 does not use the proper pointer after an audio API change, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors, which triggers a heap-based buffer overflow. Ubuntu-Description: Notes: jdstrand> from upstream, "Wrong pointer being used to write after recent audio API change." mdeslaur> doesn't look like it affects libav 0.7 and older, and ffmpeg 0.5 Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: Patches_ffmpeg: upstream: 6d8e6fe9dbc365f50521cf0c4a5ffee97c970cb5 upstream_ffmpeg: needs-triage hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: not-affected maverick_ffmpeg: ignored (reached end-of-life) natty_ffmpeg: DNE oneiric_ffmpeg: DNE precise_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: not-affected maverick_ffmpeg-extra: ignored (reached end-of-life) natty_ffmpeg-extra: DNE oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream: http://git.libav.org/?p=libav.git;a=commit;h=529a25d6e5c3ff889257a57042872d84dc2312d5 upstream_libav: released (0.8.0) hardy_libav: DNE lucid_libav: DNE maverick_libav: DNE natty_libav: not-affected oneiric_libav: not-affected precise_libav: not-affected (4:0.8.1-0ubuntu1) devel_libav: not-affected (4:0.8.1-0ubuntu2) Patches_libav-extra: upstream_libav-extra: needs-triage hardy_libav-extra: DNE lucid_libav-extra: DNE natty_libav-extra: not-affected oneiric_libav-extra: not-affected precise_libav-extra: not-affected (4:0.8.1ubuntu1) devel_libav-extra: not-affected (4:0.8.1ubuntu1)