CVE-2011-2161
Publication date 20 May 2011
Last updated 24 July 2024
Ubuntu priority
The ape_read_header function in ape.c in libavformat in FFmpeg before 0.5.4, as used in MPlayer, VideoLAN VLC media player, and other products, allows remote attackers to cause a denial of service (application crash) via an APE (aka Monkey's Audio) file that contains a header but no frames.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | ||
ffmpeg-extra | ||
libav | ||
libav-extra | ||
Notes
mdeslaur
ffmpeg-extra in multiverse needs to have matching version PoC: http://packetstorm.linuxsecurity.com/1103-exploits/vlc105-dos.txt
Patch details
Package | Patch details |
---|---|
ffmpeg | |
libav |
References
Related Ubuntu Security Notices (USN)
- USN-1209-1
- FFmpeg vulnerabilities
- 19 September 2011