Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2012-6615

Published: 24 December 2013

The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dialog without text.

Notes

AuthorNote
alexmurray
The Debian chromium source package is called chromium-browser in
Ubuntu
mdeslaur
starting with Ubuntu 19.10, the chromium-browser package is just
a script that installs the Chromium snap

Priority

Medium

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
impish Not vulnerable
(code not present)
hirsute Not vulnerable
(code not present)
jammy Not vulnerable
(code not present)
bionic Not vulnerable

focal Not vulnerable
(code not present)
groovy Not vulnerable
(code not present)
kinetic Not vulnerable
(code not present)
lunar Not vulnerable
(code not present)
trusty Does not exist

upstream
Released
xenial Not vulnerable

libav
Launchpad, Ubuntu, Debian
impish Does not exist

hirsute Does not exist

jammy Does not exist

trusty Needs triage

lunar Does not exist

bionic Does not exist

focal Does not exist

groovy Does not exist

kinetic Does not exist

upstream Not vulnerable
(debian: Vulnerable code not present in libav)
xenial Does not exist

ffmpeg
Launchpad, Ubuntu, Debian
impish Not vulnerable

hirsute Not vulnerable

jammy Not vulnerable

bionic Not vulnerable

focal Not vulnerable

kinetic Not vulnerable

lunar Not vulnerable

groovy Not vulnerable

trusty Does not exist

upstream
Released (1.0.2)
xenial Not vulnerable

Patches:
upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=20c121c00747d6c3b0b0f98deeff021171b2ed74
oxide-qt
Launchpad, Ubuntu, Debian
impish Does not exist

bionic Does not exist

focal Does not exist

groovy Does not exist

hirsute Does not exist

jammy Does not exist

xenial Needs triage

trusty Does not exist

lunar Does not exist

kinetic Does not exist

upstream Needs triage

gst-libav1.0
Launchpad, Ubuntu, Debian
groovy Ignored
(end of life)
upstream Needs triage

trusty Does not exist

bionic Needs triage

focal Needs triage

hirsute Ignored
(end of life)
jammy Needs triage

xenial Needs triage

impish Ignored
(end of life)
kinetic Ignored
(end of life, was needs-triage)
lunar Needs triage

mythtv
Launchpad, Ubuntu, Debian
upstream Needs triage

trusty Does not exist

bionic Needs triage

focal Needs triage

hirsute Ignored
(end of life)
kinetic Ignored
(end of life, was needs-triage)
jammy Needs triage

xenial Needs triage

impish Ignored
(end of life)
lunar Needs triage

groovy Ignored
(end of life)
qtwebengine-opensource-src
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

hirsute Ignored
(end of life)
kinetic Ignored
(end of life, was needs-triage)
jammy Needs triage

impish Ignored
(end of life)
lunar Needs triage

groovy Ignored
(end of life)
trusty Does not exist

upstream Needs triage

xenial Does not exist

vice
Launchpad, Ubuntu, Debian
hirsute Ignored
(end of life)
kinetic Ignored
(end of life, was needs-triage)
jammy Needs triage

xenial Needs triage

impish Ignored
(end of life)
lunar Needs triage

bionic Needs triage

focal Needs triage

groovy Ignored
(end of life)
trusty Does not exist

upstream Needs triage