CVE-2012-0852 PUBLISHED CVSS 6.800000190734863 MEDIUM

The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an ADPCM file with the number of channels not equal to two.

EPSS 2.28% · 84.5th percentile

Risk Scores

CVSS v2.0
6.800000190734863
EPSS Score
2.28%
84.5th percentile

Affected Products

VendorProductVersions
ffmpegffmpeg0.8.6, 0.8.7, 0.8.8
libavlibav0.6.5, 0.7, 0.7.1
n/an/an/a

Timeline

References

Open in Interactive Console →