CVE-2011-4031
Severity CVSS v4.0:
Pending analysis
Type:
CWE-191
Integer Underflow (Wrap or Wraparound)
Publication date:
09/05/2012
Last modified:
11/04/2025
Description
Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | 0.8.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dcommit%3Bh%3Dc2a2ad133eb9d42361804a568dee336992349a5e
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dshortlog%3Bh%3Dn0.8.3
- http://technet.microsoft.com/en-us/security/msvr/msvr11-012
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dcommit%3Bh%3Dc2a2ad133eb9d42361804a568dee336992349a5e
- http://git.videolan.org/?p=ffmpeg.git%3Ba%3Dshortlog%3Bh%3Dn0.8.3
- http://technet.microsoft.com/en-us/security/msvr/msvr11-012



