Описание
The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted media file.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| hardy | ignored | end of life |
| lucid | not-affected | code not present |
| natty | DNE | |
| oneiric | DNE | |
| precise | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| hardy | DNE | |
| lucid | not-affected | code not present |
| natty | DNE | |
| oneiric | DNE | |
| precise | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4:0.8.1-0ubuntu2 |
| hardy | DNE | |
| lucid | DNE | |
| natty | released | 4:0.6.6-0ubuntu0.11.04.1 |
| oneiric | released | 4:0.7.6-0ubuntu0.11.10.1 |
| precise | not-affected | 4:0.8.1-0ubuntu1 |
| upstream | released | 0.6.6,0.7.5,0.8.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4:0.8.1ubuntu1 |
| hardy | DNE | |
| lucid | DNE | |
| natty | released | |
| oneiric | released | |
| precise | not-affected | 4:0.8.1ubuntu1 |
| upstream | needs-triage |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted media file.
The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcode ...
The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted media file.
EPSS
6.8 Medium
CVSS2