CVE-2011-4352: Buffer Overflow
Integer overflow in the vp3dequant function in the VP3 decoder (vp3.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VP3 stream, which triggers a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4352?
CVE-2011-4352 is considered to have a medium severity level as it allows remote attackers to cause a denial of service.
How do I fix CVE-2011-4352?
To fix CVE-2011-4352, you should upgrade to a patched version of FFmpeg or Libav, specifically versions 0.5.7, 0.6.4, 0.7.9, and 0.8.8 or higher.
What software is affected by CVE-2011-4352?
CVE-2011-4352 affects multiple versions of FFmpeg and Libav, specifically versions prior to 0.5.7, 0.6.4, 0.7.9, and 0.8.8.
What type of vulnerability is CVE-2011-4352?
CVE-2011-4352 is an integer overflow vulnerability found in the VP3 decoder.
Can CVE-2011-4352 lead to remote code execution?
No, CVE-2011-4352 specifically allows for denial of service, not remote code execution.