4.3
CVSSv2

CVE-2011-4353

Published: 20/08/2012 Updated: 21/08/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff functions in FFmpeg 0.5.x prior to 0.5.7, 0.6.x prior to 0.6.4, 0.7.x prior to 0.7.9, and 0.8.x prior to 0.8.8; and in Libav 0.5.x prior to 0.5.6, 0.6.x prior to 0.6.4, and 0.7.x prior to 0.7.3 allow remote malicious users to cause a denial of service (out-of-bounds read) via a crafted VP5 or VP6 stream.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 0.5.3

ffmpeg ffmpeg 0.5.4

ffmpeg ffmpeg 0.5.5

ffmpeg ffmpeg 0.6

ffmpeg ffmpeg 0.8.5

ffmpeg ffmpeg 0.8.6

ffmpeg ffmpeg 0.8.7

ffmpeg ffmpeg 0.7.2

ffmpeg ffmpeg 0.7.3

ffmpeg ffmpeg 0.7.6

ffmpeg ffmpeg 0.7.7

ffmpeg ffmpeg 0.5.1

ffmpeg ffmpeg 0.6.2

ffmpeg ffmpeg 0.7.1

ffmpeg ffmpeg 0.7.8

ffmpeg ffmpeg 0.8.1

ffmpeg ffmpeg 0.5

ffmpeg ffmpeg 0.5.2

ffmpeg ffmpeg 0.6.1

ffmpeg ffmpeg 0.7

ffmpeg ffmpeg 0.8.0

ffmpeg ffmpeg 0.8.2

libav libav 0.5

libav libav 0.7.1

libav libav 0.7.2

libav libav 0.5.5

libav libav 0.6.2

libav libav 0.6.4

libav libav 0.6.3

libav libav 0.5.1

libav libav 0.5.3

libav libav 0.6.5

libav libav 0.7

libav libav 0.5.2

libav libav 0.5.4

libav libav 0.6.1

libav libav 0.6

Vendor Advisories

Libav could be made to crash or run programs as your login if it opened a specially crafted file ...
FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file ...
Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder Multiple input validations in the decoders for QDM2, VP5, VP6, VMD and SVQ1 files could lead to the execution of arbitrary code For the stable distribution (squeeze), this problem has been fixed in version 4:056-3 For the unstable distribution (sid) ...