Input validation error in FFmpeg and Libav - CVE-2011-3937
Published: January 5, 2013 / Updated: August 11, 2020
Libav
FFmpeg
Libav
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and attack vectors related to "width/height changing with frame threads."