The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 data.
References
Link | Resource |
---|---|
http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=68e48ed72e0597ae61bc3e9e6e6d9edcb1a00073 | Exploit Patch |
http://secunia.com/advisories/51964 | Vendor Advisory |
http://www.osvdb.org/93242 | |
http://www.ffmpeg.org/security.html | |
https://trac.ffmpeg.org/ticket/2087 | Exploit |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-12-24 12:55
Updated : 2013-12-26 07:40
NVD link : CVE-2012-6616
Mitre link : CVE-2012-6616
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
ffmpeg
- ffmpeg