First published: Mon Aug 20 2012(Updated: )
Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =0.7.7 | |
FFmpeg | =0.7.1 | |
FFmpeg | =0.7.6 | |
FFmpeg | =0.8.6 | |
FFmpeg | =0.6.1 | |
FFmpeg | =0.7.5 | |
FFmpeg | =0.5 | |
FFmpeg | =0.5.4 | |
FFmpeg | =0.5.1 | |
FFmpeg | =0.8.5 | |
FFmpeg | =0.7.3 | |
FFmpeg | =0.7.4 | |
FFmpeg | =0.8.0 | |
FFmpeg | =0.5.5 | |
FFmpeg | =0.6 | |
FFmpeg | =0.5.3 | |
FFmpeg | =0.5.2 | |
FFmpeg | =0.7.8 | |
FFmpeg | =0.6.2 | |
FFmpeg | =0.8.7 | |
FFmpeg | =0.7 | |
FFmpeg | =0.8.1 | |
FFmpeg | =0.6.3 | |
FFmpeg | =0.8.2 | |
FFmpeg | =0.7.2 | |
libavutil | =0.7-beta2 | |
libavutil | =0.7 | |
libavutil | =0.5.3 | |
libavutil | =0.6.2 | |
libavutil | =0.5 | |
libavutil | =0.7.1 | |
libavutil | =0.5.2 | |
libavutil | =0.5.5 | |
libavutil | =0.6.3 | |
libavutil | =0.7.2 | |
libavutil | =0.5.4 | |
libavutil | =0.6.1 | |
libavutil | =0.6 | |
libavutil | =0.5.1 | |
libavutil | =0.7-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4364 is classified as a high severity vulnerability due to its potential for causing denial of service and crashes in affected software.
To fix CVE-2011-4364, upgrade FFmpeg or Libav to a version that is patched, specifically versions 0.5.7, 0.6.4, 0.7.9, or 0.8.8 for FFmpeg and 0.5.6 or higher for Libav.
Affected versions of FFmpeg include 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8.
Libav versions affected by CVE-2011-4364 include 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3.
CVE-2011-4364 allows remote attackers to exploit a buffer overflow, potentially leading to a denial of service attack by crashing the affected application.