CVE-2012-2801 Affecting ffmpeg package, versions <7:2.4.1-1


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
2.97% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-FFMPEG-18234441
  • published23 Jul 2026
  • disclosed10 Sept 2012

Introduced: 10 Sep 2012

CVE-2012-2801  (opens in a new tab)

How to fix?

Upgrade Echo:latest ffmpeg to version 7:2.4.1-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ffmpeg package and not the ffmpeg package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."

CVSS Base Scores

version 3.1