6.8
CVSSv2

CVE-2011-3362

Published: 02/10/2011 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg prior to 0.7.3 and 0.8.x prior to 0.8.2, and libav up to and including 0.7.1, allows remote malicious users to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 0.7.1

ffmpeg ffmpeg 0.4.5

ffmpeg ffmpeg 0.3.2

ffmpeg ffmpeg 0.4.7

ffmpeg ffmpeg 0.6.1

ffmpeg ffmpeg 0.3.3

ffmpeg ffmpeg 0.3

ffmpeg ffmpeg 0.4.2

ffmpeg ffmpeg

ffmpeg ffmpeg 0.5

ffmpeg ffmpeg 0.5.4

ffmpeg ffmpeg 0.5.1

ffmpeg ffmpeg 0.3.1

ffmpeg ffmpeg 0.4.9

ffmpeg ffmpeg 0.6

ffmpeg ffmpeg 0.5.3

ffmpeg ffmpeg 0.4.4

ffmpeg ffmpeg 0.5.2

ffmpeg ffmpeg 0.4.6

ffmpeg ffmpeg 0.3.4

ffmpeg ffmpeg 0.4.0

ffmpeg ffmpeg 0.6.2

ffmpeg ffmpeg 0.4.8

ffmpeg ffmpeg 0.4.3

ffmpeg ffmpeg 0.8.0

ffmpeg ffmpeg 0.8.1

libav libav 0.4.1

libav libav 0.4.7

libav libav 0.3.3

libav libav 0.7

libav libav 0.4.8

libav libav 0.6.2

libav libav 0.5

libav libav 0.4.4

libav libav

libav libav 0.4.9

libav libav 0.4.5

libav libav 0.5.4

libav libav 0.3.1

libav libav 0.4.3

libav libav 0.4.2

libav libav 0.3

libav libav 0.3.2

libav libav 0.4.6

libav libav 0.6.1

libav libav 0.4.0

libav libav 0.3.4

libav libav 0.6

Vendor Advisories

Debian Bug report logs - #641478 libavcodec insufficient boundary check in CAVS decoding Package: libav; Maintainer for libav is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 13 Sep 2011 16:45:02 UTC Severity: ...
Libav could be made to run programs as your login if it opened a specially crafted file ...
FFmpeg could be made to run programs as your login if it opened a specially crafted file ...
Multiple vulnerabilities were found in FFmpeg, a multimedia player, server and encoder: CVE-2011-3362 An integer signedness error in decode_residual_block function of the Chinese AVS video (CAVS) decoder in libavcodec can lead to denial of service (memory corruption and application crash) or possible code execution via a crafted CA ...