CVE-2012-0853
Publication date 14 February 2012
Last updated 24 July 2024
Ubuntu priority
The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (infinite loop and crash) and possibly execute arbitrary code via a large component count in an Atrac 3 file.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.10 maverick | Ignored end of life | |
10.04 LTS lucid |
Fixed 4:0.5.9-0ubuntu0.10.04.1
|
|
8.04 LTS hardy | Ignored end of life | |
ffmpeg-extra | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.10 maverick | Ignored end of life | |
10.04 LTS lucid |
Fixed
|
|
8.04 LTS hardy | Not in release | |
libav | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Fixed 4:0.7.6-0ubuntu0.11.10.1
|
|
11.04 natty |
Fixed 4:0.6.6-0ubuntu0.11.04.1
|
|
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
libav-extra | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Fixed
|
|
11.04 natty |
Fixed
|
|
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Patch details
Package | Patch details |
---|---|
ffmpeg | |
libav |
References
Related Ubuntu Security Notices (USN)
- USN-1478-1
- Libav vulnerabilities
- 18 June 2012
- USN-1479-1
- FFmpeg vulnerabilities
- 18 June 2012