Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ffmpeg | — | Upgrade to FFmpeg version 0.8.3 | Sep 29, 2017 | May 9, 2012 |
| Freebsd | — | Upgrade gstreamer-ffmpeg | Dec 10, 2025 | Aug 20, 2013 |
| Ubuntu | — | Upgrade libavformat52Upgrade libavcodec52Upgrade libavformat53Upgrade libavcodec53 | Nov 8, 2024 | May 9, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub