Name | CVE-2012-0858 |
Description | The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Shorten file, related to an "invalid free". |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-2624-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
ffmpeg (PTS) | stretch (security) | 7:3.2.18-0+deb9u1 | fixed |
stretch (lts), stretch | 7:3.2.19-0+deb9u5 | fixed | |
buster, buster (lts) | 7:4.1.11-0+deb10u2 | fixed | |
buster (security) | 7:4.1.11-0+deb10u1 | fixed | |
bullseye | 7:4.3.7-0+deb11u1 | fixed | |
bullseye (security) | 7:4.3.8-0+deb11u1 | fixed | |
bookworm (security), bookworm | 7:5.1.6-0+deb12u1 | fixed | |
sid, trixie | 7:7.1-3 | fixed | |
libav (PTS) | jessie, jessie (lts) | 6:11.12-1~deb8u9 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
ffmpeg | source | squeeze | 4:0.5.10-1 | DSA-2624-1 | ||
ffmpeg | source | (unstable) | 7:2.2.1-1 | |||
libav | source | (unstable) | 4:0.8.1-1 |