Input validation error in FFmpeg and Libav - CVE-2011-3937

 

Input validation error in FFmpeg and Libav - CVE-2011-3937

Published: January 5, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU43212
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2011-3937
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ffmpeg.sourceforge.net
Libav
Affected software:
FFmpeg
Libav

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and attack vectors related to "width/height changing with frame threads."


How to mitigate CVE-2011-3937

Install update from vendor's website.

Sources