Out-of-bounds read in FFmpeg and Libav - CVE-2011-3936
Published: August 20, 2012 / Updated: August 11, 2020
Libav
FFmpeg
Libav
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the libavcodec function in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and file. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and crash the affected application.
How to mitigate CVE-2011-3936
Sources
- http://ffmpeg.org/
- http://git.libav.org/?p=libav.git;a=commit;h=635bcfccd439480003b74a665b5aa7c872c1ad6b
- http://git.libav.org/?p=libav.git;a=commitdiff;h=2d1c0dea5f6b91bec7f5fa53ec050913d851e366
- http://libav.org/
- http://secunia.com/advisories/49089
- http://www.debian.org/security/2012/dsa-2471
- http://www.ubuntu.com/usn/USN-1479-1