CVE-2011-3952
Publication date 22 May 2012
Last updated 24 July 2024
Ubuntu priority
Description
The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large palette size in a KMVC encoded file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ffmpeg | ||
| ffmpeg-extra | ||
| libav | ||
| libav-extra | ||
Notes
mdeslaur
ffmpeg-extra in multiverse needs to have matching version libav-extra is built with tarball produced by libav package as of 2012-05-29, doesn't seem to be fixed in libav 0.7 as of 2012-05-29, doesn't seem to be fixed in ffmpeg 0.5.x
Patch details
| Package | Patch details |
|---|---|
| ffmpeg | |
| libav |
References
Related Ubuntu Security Notices (USN)
- USN-1478-1
- Libav vulnerabilities
- 18 June 2012
- USN-1479-1
- FFmpeg vulnerabilities
- 18 June 2012