Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-6615

Опубликовано: 24 дек. 2013
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dialog without text.

Комментарий

Per: http://cwe.mitre.org/data/definitions/476.html

"CWE-476: NULL Pointer Dereference"

AC:M for notation of file in bug report

" ffmpeg crashes reproducibly when converting files with some subtitles. i've seen the crash with self-compiled ffmpeg 1.0 as well as the Mac OS X binary (linked to from the hompage) for 1.0.1.

download the sample file: ?https://dl.dropbox.com/u/7221986/ffmpeg-bug.mkv"

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Версия до 1.0.1 (включая)
cpe:2.3:a:ffmpeg:ffmpeg:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.0083
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 12 лет назад

The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dialog without text.

debian
около 12 лет назад

The ff_ass_split_override_codes function in libavcodec/ass_split.c in ...

github
больше 3 лет назад

The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dialog without text.

EPSS

Процентиль: 74%
0.0083
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other