CVE-2007-3329

Publication date 21 June 2007

Last updated 17 July 2025


Ubuntu priority

Description

Multiple array index errors in the (1) get_intra_block, (2) get_inter_block_h263, and (3) get_inter_block_mpeg functions in src/bitstream/mbcoding.c in Xvid 1.1.2 allow remote attackers to execute arbitrary code via a crafted (a) Avi, (b) H.263, or (c) MPEG file.

Status

Package Ubuntu Release Status
xvidcore 9.10 karmic
Fixed 1.1.2-0.1ubuntu3
9.04 jaunty
Fixed 1.1.2-0.1ubuntu3
8.10 intrepid
Fixed 1.1.2-0.1ubuntu3
8.04 LTS hardy
Fixed 1.1.2-0.1ubuntu3
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life