Buffer overflow in FFmpeg - CVE-2011-4364

 

Buffer overflow in FFmpeg - CVE-2011-4364

Published: August 20, 2012 / Updated: June 8, 2025


Vulnerability identifier: #VU43687
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4364
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.


Affected software

FFmpeg

How to mitigate CVE-2011-4364

Install update from vendor's website.

FFmpeg - addressed in versions 0.5.7, 0.6.4, 0.7.9, 0.8.8

External References

Related Security Bulletins