CVE-2011-3362
Severity CVSS v4.0:
Pending analysis
Type:
CWE-189
Numeric Errors
Publication date:
02/10/2011
Last modified:
11/04/2025
Description
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | 0.7.2 (including) | |
cpe:2.3:a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.9:pre1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dcommit%3Bh%3D91d5da9321c52e8197fb14046ebb335f3e6ff4a0
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dcommit%3Bh%3Dc5cbda50793e311aa73489d12184ffd6761c9fbf
- http://secunia.com/advisories/45532
- http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changelog
- http://www.ffmpeg.org/releases/ffmpeg-0.8.4.changelog
- http://www.ocert.org/advisories/ocert-2011-002.html
- http://www.openwall.com/lists/oss-security/2011/09/13/4
- http://www.openwall.com/lists/oss-security/2011/09/14/8
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dcommit%3Bh%3D91d5da9321c52e8197fb14046ebb335f3e6ff4a0
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dcommit%3Bh%3Dc5cbda50793e311aa73489d12184ffd6761c9fbf
- http://secunia.com/advisories/45532
- http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changelog
- http://www.ffmpeg.org/releases/ffmpeg-0.8.4.changelog
- http://www.ocert.org/advisories/ocert-2011-002.html
- http://www.openwall.com/lists/oss-security/2011/09/13/4
- http://www.openwall.com/lists/oss-security/2011/09/14/8