Back to search
CVE-2011-3362
Published: Oct 2, 2011
Modified: Sep 16, 2024
PUBLISHED
Description
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
45532
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20110913 CVE request: ffmpeg/libav insufficuent boundary check in CAVS decoding
mailing-list
x_refsource_MLIST
http://www.ffmpeg.org/releases/ffmpeg-0.8.4.changelog
x_refsource_CONFIRM
http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changelog
x_refsource_CONFIRM
[oss-security] 20110914 Re: CVE request: ffmpeg/libav insufficuent boundary check in CAVS decoding
mailing-list
x_refsource_MLIST
http://www.ocert.org/advisories/ocert-2011-002.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now