CVE-2011-3362: Medium severity ffmpeg vulnerability
Integer signedness error in the decoderesidualblock function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3362?
CVE-2011-3362 is classified as a denial of service vulnerability that can potentially lead to memory corruption and application crashes.
How do I fix CVE-2011-3362?
To fix CVE-2011-3362, upgrade FFmpeg to version 0.7.3 or later, or update Libav to version 0.7.2 or later.
What software is affected by CVE-2011-3362?
CVE-2011-3362 affects FFmpeg versions before 0.7.3 and 0.8.x before 0.8.2, as well as Libav versions through 0.7.1.
What are the potential impacts of CVE-2011-3362?
The potential impacts of CVE-2011-3362 include application crashes and the possibility of executing arbitrary code by remote attackers.
Is CVE-2011-3362 still a relevant vulnerability today?
While CVE-2011-3362 is outdated, it may still pose a risk for legacy software systems that have not been updated.