CVE-2012-0856

Heap-based buffer overflow in the MPV_frame_start function in libavcodec/mpegvideo.c in FFmpeg before 0.9.1, when the lowres option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted H263 media file. NOTE: this vulnerability exists because of a regression error.

Date published : 2012-08-20

http://ffmpeg.org/security.html

http://ffmpeg.org/trac/ffmpeg/ticket/757