CVE-2011-3945: Buffer Overflow
The decodeframe function in the KVG1 decoder (kgv1dec.c) in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted media file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3945?
CVE-2011-3945 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2011-3945?
To fix CVE-2011-3945, upgrade to FFmpeg version 0.7.12 or later, or 0.8.11 or later, or Libav version 0.5.9, 0.6.6, 0.7.5, or 0.8.1.
What types of systems are affected by CVE-2011-3945?
CVE-2011-3945 affects various versions of FFmpeg and Libav before their respective patch releases.
How can CVE-2011-3945 be exploited by attackers?
Attackers can exploit CVE-2011-3945 to craft malicious video files that may crash affected applications.
What are the potential impacts of CVE-2011-3945?
The potential impacts of CVE-2011-3945 include application crashes and denial of service conditions on vulnerable systems.