CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
89.5%
The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before
0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before
0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of
service (application crash) and possibly execute arbitrary code via an
ADPCM file with the number of channels not equal to two.
Author | Note |
---|---|
mdeslaur | as of 2012-05-22, no equivalent fix in libav as of 2012-05-22, no equivalent fix in ffmpeg 0.5.x |