Resource management error in FFmpeg - CVE-2012-2803
Published: September 11, 2012 / Updated: June 8, 2025
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.
Affected software
How to mitigate CVE-2012-2803
External References
- http://ffmpeg.org/security.html
- http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=951cbea56fdc03ef96d07fbd7e5bed755d42ac8a
- http://libav.org/releases/libav-0.7.7.changelog
- http://libav.org/releases/libav-0.8.5.changelog
- http://secunia.com/advisories/50468
- http://www.openwall.com/lists/oss-security/2012/08/31/3
- http://www.openwall.com/lists/oss-security/2012/09/02/4
- http://www.securityfocus.com/bid/55355
- http://www.ubuntu.com/usn/USN-1705-1
- http://www.ubuntu.com/usn/USN-1706-1