Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-2161
HistoryMay 20, 2011 - 12:00 a.m.

CVE-2011-2161

2011-05-2000:00:00
ubuntu.com
ubuntu.com
17

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.003

Percentile

68.9%

The ape_read_header function in ape.c in libavformat in FFmpeg before
0.5.4, as used in MPlayer, VideoLAN VLC media player, and other products,
allows remote attackers to cause a denial of service (application crash)
via an APE (aka Monkey’s Audio) file that contains a header but no frames.

Bugs

Notes

Author Note
mdeslaur ffmpeg-extra in multiverse needs to have matching version PoC: http://packetstorm.linuxsecurity.com/1103-exploits/vlc105-dos.txt
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchffmpeg< 4:0.5.1-1ubuntu1.2UNKNOWN
ubuntu10.10noarchffmpeg< 4:0.6-2ubuntu6.2UNKNOWN
ubuntu10.04noarchffmpeg-extra< 4:0.5.1-1ubuntu1.3UNKNOWN
ubuntu10.10noarchffmpeg-extra< 4:0.6-2ubuntu3.3UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.003

Percentile

68.9%