CVE-2011-3940
Published: 13 May 2012
nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted NSV file that triggers "use of uninitialized streams."
Notes
Author | Note |
---|---|
mdeslaur | ffmpeg-extra in multiverse needs to have matching version libav-extra is built with tarball produced by libav package |
Priority
Status
Package | Release | Status |
---|---|---|
ffmpeg Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Released
(4:0.5.9-0ubuntu0.10.04.1)
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
upstream |
Released
(0.5.9)
|
|
Patches: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=5c011706bc752d34bc6ada31d7df2ca0c9af7c6b upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8fd8a48263ff1437f9d02d7e78dc63efb9b5ed3a upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=c898431ca5ef2a997fe9388b650f658fb60783e5 |
||
ffmpeg-extra Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Released
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
upstream |
Needs triage
|
|
libav Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
natty |
Released
(4:0.6.6-0ubuntu0.11.04.1)
|
|
oneiric |
Released
(4:0.7.6-0ubuntu0.11.10.1)
|
|
precise |
Not vulnerable
(4:0.8.1-0ubuntu1)
|
|
upstream |
Released
(0.6.6,0.7.5,0.8.1)
|
|
libav-extra Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
natty |
Released
|
|
oneiric |
Released
|
|
precise |
Not vulnerable
(4:0.8.1ubuntu1)
|
|
upstream |
Needs triage
|