Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-3951
HistoryMay 22, 2012 - 12:00 a.m.

CVE-2011-3951

2012-05-2200:00:00
ubuntu.com
ubuntu.com
13

0.013 Low

EPSS

Percentile

85.7%

The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before
0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before
0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of
service (application crash) and possibly execute arbitrary code via a
crafted stereo stream in a media file.

Notes

Author Note
mdeslaur ffmpeg-extra in multiverse needs to have matching version libav-extra is built with tarball produced by libav package as of 2012-05-29, no fix in ffmpeg 0.5.x
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchffmpeg< 4:0.5.9-0ubuntu0.10.04.1UNKNOWN
ubuntuupstreamnoarchffmpeg< anyUNKNOWN
ubuntuupstreamnoarchffmpeg-extra< anyUNKNOWN
ubuntu11.04noarchlibav< 4:0.6.6-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchlibav< 4:0.7.6-0ubuntu0.11.10.1UNKNOWN
ubuntuupstreamnoarchlibav< 0.8.1,0.7.6,0.6.6UNKNOWN
ubuntuupstreamnoarchlibav-extra< anyUNKNOWN