---
title: "CVE-2011-3937\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-3937?format=md
keywords: index, follow
---

# CVE-2011-3937

Publication date 5 January 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x
before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x
before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before
0.8.1 has unspecified impact and attack vectors related to "width/height
changing with frame threads."

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-3937?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ffmpeg | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Ignored end of life |
| ffmpeg-extra | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |
| libav | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| libav-extra | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-3937?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

ffmpeg-extra in multiverse needs to have matching version
libav-extra is built with tarball produced by libav package
libav upstream says fixed multithreaded decoding which was
introduced in 0.7, so older releases not affected.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| ffmpeg | * Upstream:   <http://git.videolan.org/?p=ffmpeg.git;a=commit;h=71db86d53b5c6872cea31bf714a1a38ec78feaba> |
| libav | * Upstream:   <http://git.libav.org/?p=libav.git;a=commit;h=71db86d53b5c6872cea31bf714a1a38ec78feaba> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3937)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-3937)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-3937)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-3937)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-3937>
