CVE-2011-3936: Input Validation
The dvextractaudio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3936?
CVE-2011-3936 has a severity rating of medium due to its potential to cause denial of service through out-of-bounds reads leading to application crashes.
How do I fix CVE-2011-3936?
To fix CVE-2011-3936, upgrade to FFmpeg version 0.7.12 or later, or 0.8.11 or later, or update to Libav version 0.5.9 or later.
Which versions are affected by CVE-2011-3936?
CVE-2011-3936 affects FFmpeg versions 0.7.x before 0.7.12 and 0.8.x before 0.8.11, as well as Libav versions 0.5.x before 0.5.9 and other specific versions.
What type of attack does CVE-2011-3936 enable?
CVE-2011-3936 enables remote attackers to cause a denial of service through manipulated media files.
What impact can CVE-2011-3936 have on systems?
The impact of CVE-2011-3936 can include application crashes, leading to potential service outages in applications using vulnerable versions of FFmpeg or Libav.