Release date:
Updated on:
Affected Systems:
FFmpeg <= 0.11.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56112
Cve id: CVE-2012-5359, CVE-2012-5360, CVE-2012-5361
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
Multiple Remote Code Execution Vulnerabilities exist in FFmpeg 0.11.2 and earlier versions. Attackers can exploit this vulnerability to execute arbitrary code in affected applications.
1) When Parsing ASF, QT, and WMV files, there is an error in the libavcodec library, which can be exploited to corrupt the memory.
2) the error in the "ff_compute_band_indexes ()" function (libavcodec/mpegaudiodec. c) can be exploited to corrupt the memory.
<* Source: Jeremy Brown
Link: http://secunia.com/advisories/50963/
Http://technet.microsoft.com/en-us/security/msvr/msvr12-017
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FFmpeg
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://ffmpeg.sourceforge.net/