CVE-2012-0853: Ffmpeg

Medium severity, CVSS 6.8. EPSS: 4.3% chance of exploitation in the next 30 days.

The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (infinite loop and crash) and possibly execute arbitrary code via a large component count in an Atrac 3 file.

Affected products

  • Ffmpeg Ffmpeg: version 0.7 only; version 0.7.1 only; version 0.7.2 only; version 0.7.3 only; version 0.7.6 only; version 0.7.7 only; …
  • Libav Libav: version 0.5 only; version 0.5.1 only; version 0.5.2 only; version 0.5.3 only; version 0.5.4 only; version 0.5.5 only; …

Published 2012-08-20. Last modified 2026-06-16.