First published: Mon Aug 20 2012(Updated: )
The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =0.7 | |
FFmpeg | =0.7.1 | |
FFmpeg | =0.7.2 | |
FFmpeg | =0.7.3 | |
FFmpeg | =0.7.6 | |
FFmpeg | =0.7.7 | |
FFmpeg | =0.7.8 | |
FFmpeg | =0.7.9 | |
FFmpeg | =0.7.11 | |
FFmpeg | =0.7.12 | |
FFmpeg | =0.8.0 | |
FFmpeg | =0.8.1 | |
FFmpeg | =0.8.2 | |
FFmpeg | =0.8.5 | |
FFmpeg | =0.8.6 | |
FFmpeg | =0.8.7 | |
FFmpeg | =0.8.8 | |
FFmpeg | =0.8.10 | |
libavutil | =0.5 | |
libavutil | =0.5.1 | |
libavutil | =0.5.2 | |
libavutil | =0.5.3 | |
libavutil | =0.5.4 | |
libavutil | =0.5.5 | |
libavutil | =0.5.6 | |
libavutil | =0.5.7 | |
libavutil | =0.6 | |
libavutil | =0.6.1 | |
libavutil | =0.6.2 | |
libavutil | =0.6.3 | |
libavutil | =0.6.4 | |
libavutil | =0.6.5 | |
libavutil | =0.7 | |
libavutil | =0.7-beta1 | |
libavutil | =0.7-beta2 | |
libavutil | =0.7.1 | |
libavutil | =0.7.2 | |
libavutil | =0.7.3 | |
libavutil | =0.7.4 | |
libavutil | =0.8 | |
libavutil | =0.8-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3936 has a severity rating of medium due to its potential to cause denial of service through out-of-bounds reads leading to application crashes.
To fix CVE-2011-3936, upgrade to FFmpeg version 0.7.12 or later, or 0.8.11 or later, or update to Libav version 0.5.9 or later.
CVE-2011-3936 affects FFmpeg versions 0.7.x before 0.7.12 and 0.8.x before 0.8.11, as well as Libav versions 0.5.x before 0.5.9 and other specific versions.
CVE-2011-3936 enables remote attackers to cause a denial of service through manipulated media files.
The impact of CVE-2011-3936 can include application crashes, leading to potential service outages in applications using vulnerable versions of FFmpeg or Libav.