Buffer overflow in FFmpeg - CVE-2011-4351

 

Buffer overflow in FFmpeg - CVE-2011-4351

Published: December 9, 2013 / Updated: August 10, 2020


Vulnerability identifier: #VU42269
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4351
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary code via unspecified vectors.


Affected software

FFmpeg

How to mitigate CVE-2011-4351

Install update from vendor's website.


External References

Related Security Bulletins