CVE-2011-3951: Buffer Overflow
The dpcmdecodeframe function in dpcm.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted stereo stream in a media file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3951?
CVE-2011-3951 has a severity rating that typically indicates a denial of service vulnerability and possible remote code execution.
How do I fix CVE-2011-3951?
To fix CVE-2011-3951, update FFmpeg to version 0.10 or later or Libav to a fixed version such as 0.5.9 for the affected releases.
Which versions of FFmpeg are affected by CVE-2011-3951?
FFmpeg versions prior to 0.10, including 0.7.x, 0.8.x, and 0.9, are affected by CVE-2011-3951.
Which versions of Libav are vulnerable to CVE-2011-3951?
Libav versions prior to 0.5.9, 0.6.6, 0.7.6, and 0.8.1 are vulnerable to CVE-2011-3951.
What types of attacks can CVE-2011-3951 be exploited for?
CVE-2011-3951 can be exploited by remote attackers to crash the application and potentially execute arbitrary code.