Input validation error in Libav and FFmpeg - CVE-2011-3937

 

Input validation error in Libav and FFmpeg - CVE-2011-3937

Published: January 5, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU43212
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3937
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and attack vectors related to "width/height changing with frame threads."


Affected software

Libav
FFmpeg
Gentoo Linux

How to mitigate CVE-2011-3937

Install update from vendor's website.


External References

Related Security Bulletins