CVE-2012-0859 describes a denial-of-service vulnerability in the render_line function of the vorbis codec within libavcodec in FFmpeg versions prior to 0.9.1. This flaw, an incomplete fix for CVE-2011-3893, allows remote attackers to crash applications and potentially execute arbitrary code through a crafted Vorbis file. With a CVSS score of 6.8, it is a medium-severity vulnerability requiring medium attack complexity and offering partial confidentiality, integrity, and availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | ||
0.7.1CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.7.1:*:*:*:*:*:*:* | ||
0.7.2CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.7.2:*:*:*:*:*:*:* | ||
0.7.7CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.7.7:*:*:*:*:*:*:* | ||
0.7.8CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.7.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
FFmpeg vorbis: Fix last quarter of CVE-2011-3893
Fix last quarter of CVE-2011-3893
Partial fix for CVE-2011-3893 in vorbis
Fix last quarter of CVE-2011-3893 in vorbis