CVE-2012-0856

low
Published 2012-08-20 · Modified 2026-04-29
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

Heap-based buffer overflow in the MPV_frame_start function in libavcodec/mpegvideo.c in FFmpeg before 0.9.1, when the lowres option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted H263 media file. NOTE: this vulnerability exists because of a regression error.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0856

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
ffmpegffmpeg{"endIncluding":"0.9"}
ffmpegffmpeg0.3
ffmpegffmpeg0.3.1
ffmpegffmpeg0.3.2
ffmpegffmpeg0.3.3
ffmpegffmpeg0.3.4
ffmpegffmpeg0.4.0
ffmpegffmpeg0.4.2
ffmpegffmpeg0.4.3
ffmpegffmpeg0.4.4
ffmpegffmpeg0.4.5
ffmpegffmpeg0.4.6
ffmpegffmpeg0.4.7
ffmpegffmpeg0.4.8
ffmpegffmpeg0.4.9
ffmpegffmpeg0.5
ffmpegffmpeg0.5.1
ffmpegffmpeg0.5.2
ffmpegffmpeg0.5.3
ffmpegffmpeg0.5.4
ffmpegffmpeg0.6
ffmpegffmpeg0.6.1
ffmpegffmpeg0.6.2
ffmpegffmpeg0.7
ffmpegffmpeg0.7.1
ffmpegffmpeg0.7.2
ffmpegffmpeg0.7.3
ffmpegffmpeg0.7.6
ffmpegffmpeg0.7.7
ffmpegffmpeg0.7.8
ffmpegffmpeg0.7.9
ffmpegffmpeg0.7.11
ffmpegffmpeg0.7.12
ffmpegffmpeg0.8.0
ffmpegffmpeg0.8.1
ffmpegffmpeg0.8.2
ffmpegffmpeg0.8.5
ffmpegffmpeg0.8.6
ffmpegffmpeg0.8.7
ffmpegffmpeg0.8.8
ffmpegffmpeg0.8.10
ffmpegffmpeg0.8.11

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.