CVE-2016-3062

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
16/06/2016
Last modified:
12/04/2025

Description

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libav:libav:*:*:*:*:*:*:*:* 11.6 (including)
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* 0.10.15 (including)
cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:* 8.0 (including)
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*