CVE-2012-0823
Published Feb 23, 2012
Last updated 4 years ago
Overview
- Description
- VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:webmproject:libvpx:*:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D28ACF69-BDF5-4370-812F-9E87B2E8DE55", "versionEndIncluding": "0.9.7" }, { "criteria": "cpe:2.3:a:webmproject:libvpx:0.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB5226F5-CC1F-45AB-BEF2-78EB10952626" }, { "criteria": "cpe:2.3:a:webmproject:libvpx:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2700C589-6AE6-4A2E-A731-B0286F945B92" }, { "criteria": "cpe:2.3:a:webmproject:libvpx:0.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7FFD43B-E901-4839-8673-9BD3EFF30536" }, { "criteria": "cpe:2.3:a:webmproject:libvpx:0.9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00E68DD8-3813-4336-8C59-0628A5E71023" }, { "criteria": "cpe:2.3:a:webmproject:libvpx:0.9.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDB30888-7893-426E-8E46-4C33AAD41ACE" }, { "criteria": "cpe:2.3:a:webmproject:libvpx:0.9.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA9033B3-2550-4E31-A142-53C5788EDC99" } ], "operator": "OR" } ] } ]