CVE-2012-2796
Last modified
CVE-2012-2796 is a vulnerability of currently unknown severity. Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to inconsistencies in "coded slice positions and interlacing" that trigger "out of array writes.". EPSS estimates a 2.89% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to inconsistencies in "coded slice positions and interlacing" that trigger "out of array writes."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | <= 0.10.4 |
| Ffmpeg | Ffmpeg | 0.3 |
| Ffmpeg | Ffmpeg | 0.3.1 |
| Ffmpeg | Ffmpeg | 0.3.2 |
| Ffmpeg | Ffmpeg | 0.3.3 |
| Ffmpeg | Ffmpeg | 0.3.4 |
| Ffmpeg | Ffmpeg | 0.4.0 |
| Ffmpeg | Ffmpeg | 0.4.2 |
| Ffmpeg | Ffmpeg | 0.4.3 |
| Ffmpeg | Ffmpeg | 0.4.4 |
| Ffmpeg | Ffmpeg | 0.4.5 |
| Ffmpeg | Ffmpeg | 0.4.6 |
| Ffmpeg | Ffmpeg | 0.4.7 |
| Ffmpeg | Ffmpeg | 0.4.8 |
| Ffmpeg | Ffmpeg | 0.4.9 |
| Ffmpeg | Ffmpeg | 0.5 |
| Ffmpeg | Ffmpeg | 0.5.1 |
| Ffmpeg | Ffmpeg | 0.5.2 |
| Ffmpeg | Ffmpeg | 0.5.3 |
| Ffmpeg | Ffmpeg | 0.5.4 |
| Ffmpeg | Ffmpeg | 0.5.4.5 |
| Ffmpeg | Ffmpeg | 0.5.4.6 |
| Ffmpeg | Ffmpeg | 0.6 |
| Ffmpeg | Ffmpeg | 0.6.1 |
| Ffmpeg | Ffmpeg | 0.6.2 |
| Ffmpeg | Ffmpeg | 0.6.3 |
| Ffmpeg | Ffmpeg | 0.7 |
| Ffmpeg | Ffmpeg | 0.7.1 |
| Ffmpeg | Ffmpeg | 0.7.2 |
| Ffmpeg | Ffmpeg | 0.7.3 |
| Ffmpeg | Ffmpeg | 0.7.4 |
| Ffmpeg | Ffmpeg | 0.7.5 |
| Ffmpeg | Ffmpeg | 0.7.6 |
| Ffmpeg | Ffmpeg | 0.7.7 |
| Ffmpeg | Ffmpeg | 0.7.8 |
| Ffmpeg | Ffmpeg | 0.7.9 |
| Ffmpeg | Ffmpeg | 0.7.11 |
| Ffmpeg | Ffmpeg | 0.7.12 |
| Ffmpeg | Ffmpeg | 0.8.0 |
| Ffmpeg | Ffmpeg | 0.8.1 |
| Ffmpeg | Ffmpeg | 0.8.2 |
| Ffmpeg | Ffmpeg | 0.8.5 |
| Ffmpeg | Ffmpeg | 0.8.5.3 |
| Ffmpeg | Ffmpeg | 0.8.5.4 |
| Ffmpeg | Ffmpeg | 0.8.6 |
| Ffmpeg | Ffmpeg | 0.8.7 |
| Ffmpeg | Ffmpeg | 0.8.8 |
| Ffmpeg | Ffmpeg | 0.8.10 |
| Ffmpeg | Ffmpeg | 0.8.11 |
| Ffmpeg | Ffmpeg | 0.9 |
Showing 50 of 57 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2796?
How severe is CVE-2012-2796?
How do I fix CVE-2012-2796?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-2790Unspecified vulnerability in the read_var_block_data functio…
- CVE-2012-2791Multiple unspecified vulnerabilities in the (1) decode_band_…
- CVE-2012-2792Unspecified vulnerability in the decode_init function in lib…
- CVE-2012-2793Unspecified vulnerability in the lag_decode_zero_run_line fu…
- CVE-2012-2794Unspecified vulnerability in the decode_mb_info function in …
- CVE-2012-2795Multiple unspecified vulnerabilities in libavcodec/wmalossle…
- CVE-2012-2797Unspecified vulnerability in the decode_frame_mp3on4 functio…
- CVE-2012-2798Unspecified vulnerability in the decode_dds1 function in lib…
- CVE-2012-2799Unspecified vulnerability in libavcodec/wmalosslessdec.c in …
- CVE-2012-2800Unspecified vulnerability in the ff_ivi_process_empty_tile f…
- CVE-2012-2801Unspecified vulnerability in libavcodec/avs.c in FFmpeg befo…
- CVE-2012-2802Unspecified vulnerability in the ac3_decode_frame function i…
Are you affected by CVE-2012-2796?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
