CVE-2011-3940: Buffer Overflow
nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted NSV file that triggers "use of uninitialized streams."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3940?
CVE-2011-3940 has a medium severity level due to its potential to cause denial of service via crafted NSV files.
How do I fix CVE-2011-3940?
To fix CVE-2011-3940, update FFmpeg to versions 0.7.12 or 0.8.11, or Libav to versions 0.5.9, 0.6.6, 0.7.5, or 0.8.1 or later.
Which versions are affected by CVE-2011-3940?
CVE-2011-3940 affects FFmpeg versions prior to 0.7.12 and 0.8.11, as well as Libav versions prior to 0.5.9, 0.6.6, 0.7.5, and 0.8.1.
What type of vulnerability is CVE-2011-3940?
CVE-2011-3940 is a denial of service vulnerability caused by out-of-bounds read and write in the nsvdec.c module.
Can CVE-2011-3940 be exploited remotely?
Yes, CVE-2011-3940 can be exploited remotely by attackers using specially crafted NSV files.