CVE-2011-3936
Published: 13 May 2012
The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.
Notes
Author | Note |
---|---|
mdeslaur | ffmpeg-extra in multiverse needs to have matching version libav-extra is built with tarball produced by libav package see patches for CVE-2011-3929 |
Priority
Status
Package | Release | Status |
---|---|---|
ffmpeg Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Released
(4:0.5.9-0ubuntu0.10.04.1)
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
upstream |
Released
(0.5.9)
|
|
ffmpeg-extra Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Released
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
upstream |
Needs triage
|
|
libav Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
natty |
Released
(4:0.6.6-0ubuntu0.11.04.1)
|
|
oneiric |
Released
(4:0.7.6-0ubuntu0.11.10.1)
|
|
precise |
Not vulnerable
(4:0.8.1-0ubuntu1)
|
|
upstream |
Released
(0.6.6,0.7.5,0.8.1)
|
|
libav-extra Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
natty |
Released
|
|
oneiric |
Released
|
|
precise |
Not vulnerable
(4:0.8.1ubuntu1)
|
|
upstream |
Needs triage
|