5
CVSSv2

CVE-2011-3974

Published: 02/10/2011 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg prior to 0.7.4 and 0.8.x prior to 0.8.3 allows remote malicious users to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 0.7.1

ffmpeg ffmpeg 0.4.5

ffmpeg ffmpeg 0.3.2

ffmpeg ffmpeg 0.4.7

ffmpeg ffmpeg 0.6.1

ffmpeg ffmpeg 0.3.3

ffmpeg ffmpeg 0.3

ffmpeg ffmpeg 0.4.2

ffmpeg ffmpeg 0.5

ffmpeg ffmpeg 0.5.4

ffmpeg ffmpeg 0.5.1

ffmpeg ffmpeg 0.3.1

ffmpeg ffmpeg 0.4.9

ffmpeg ffmpeg 0.6

ffmpeg ffmpeg 0.5.3

ffmpeg ffmpeg 0.4.4

ffmpeg ffmpeg 0.5.2

ffmpeg ffmpeg

ffmpeg ffmpeg 0.4.6

ffmpeg ffmpeg 0.3.4

ffmpeg ffmpeg 0.4.0

ffmpeg ffmpeg 0.6.2

ffmpeg ffmpeg 0.4.8

ffmpeg ffmpeg 0.4.3

ffmpeg ffmpeg 0.7.2

ffmpeg ffmpeg 0.8.0

ffmpeg ffmpeg 0.8.1

ffmpeg ffmpeg 0.8.2

Vendor Advisories

Multiple vulnerabilities were found in FFmpeg, a multimedia player, server and encoder: CVE-2011-3362 An integer signedness error in decode_residual_block function of the Chinese AVS video (CAVS) decoder in libavcodec can lead to denial of service (memory corruption and application crash) or possible code execution via a crafted CA ...