CVE-2012-0858
ffmpeg - several
EPSS 2.8%
Description
The Shorten codec (shorten.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Shorten file, related to an "invalid free".
How to fix CVE-2012-0858
To remediate CVE-2012-0858, upgrade the affected package to a fixed version below.
- Debian/ffmpeg—upgrade to 7:2.2.1-1 or later
- Debian/ffmpeg—upgrade to 4:0.5.10-1 or later
Is CVE-2012-0858 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 7:2.2.1-1
- from 0, < 4:0.5.10-1