2024-07-14 02:06:08 +00:00

162 lines
5.7 KiB
JSON

{
"id": "CVE-2012-0859",
"sourceIdentifier": "secalert@redhat.com",
"published": "2012-08-20T18:55:02.903",
"lastModified": "2023-11-07T02:10:04.860",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893."
},
{
"lang": "es",
"value": "La funci\u00f3n render_line en el codec Vorbis (vorbis.c) en libavcodec de FFmpeg antes de v0.9.1 permite a atacantes remotos provocar una denegaci\u00f3n de servicio (por ca\u00edda de la aplicaci\u00f3n) y posiblemente ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de un archivo Vorbis modificado, a\u00f1adiendo un multiplicador de gran tama\u00f1o. NOTA: esta vulnerabilidad se debe a un arreglo incompleto para CVE-2011-3893.\r\n"
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.9",
"matchCriteriaId": "D15FD45D-03F0-4EA0-9CEB-B7E7C62478D0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "07669E0E-8C4B-430E-802F-F64EEA2B5A0B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.2:*:*:*:*:*:*:*",
"matchCriteriaId": "F3EB7F17-F25D-4E48-8A43-F799619CE71F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.7:*:*:*:*:*:*:*",
"matchCriteriaId": "AAA31D75-C3FB-4D89-8B2D-21372AAEB78B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.8:*:*:*:*:*:*:*",
"matchCriteriaId": "B20E5358-826C-47A2-B39F-ED4E9213BA95"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.9:*:*:*:*:*:*:*",
"matchCriteriaId": "26321888-E140-4F09-AAA0-7392AA7F6307"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.11:*:*:*:*:*:*:*",
"matchCriteriaId": "7E46B9F3-A9C0-4B8A-A119-40CA4CBBD0EE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.7.12:*:*:*:*:*:*:*",
"matchCriteriaId": "44800572-71C5-4AA1-9CB6-30AA902B0353"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.8.5:*:*:*:*:*:*:*",
"matchCriteriaId": "CE9D7B73-9CDA-4BAE-8DD9-8E1E34C20648"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.8.6:*:*:*:*:*:*:*",
"matchCriteriaId": "F428A2E4-A54F-4296-A00F-1A4E160253D7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.8.7:*:*:*:*:*:*:*",
"matchCriteriaId": "5239E4FA-0359-49F1-93D4-24AB013FAC20"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.8.8:*:*:*:*:*:*:*",
"matchCriteriaId": "F0C8230D-4E89-45F9-B0F7-E317119E0FA0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.8.10:*:*:*:*:*:*:*",
"matchCriteriaId": "585CE7D2-1CE8-44AB-AE67-07D7D3721F68"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ffmpeg:ffmpeg:0.8.11:*:*:*:*:*:*:*",
"matchCriteriaId": "EE81C339-A794-4303-B829-BE743DF0B132"
}
]
}
]
}
],
"references": [
{
"url": "http://ffmpeg.org/security.html",
"source": "secalert@redhat.com"
},
{
"url": "http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=6fcf2bb8af0e7d6bb179e71e67e5fab8ef0d2ec2",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/02/14/4",
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1479-1",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78925",
"source": "secalert@redhat.com"
}
]
}