---
title: "CVE-2011-3951\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-3951?format=md
keywords: index, follow
---

# CVE-2011-3951

Publication date 22 May 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The dpcm\_decode\_frame function in dpcm.c in libavcodec in FFmpeg before
0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before
0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of
service (application crash) and possibly execute arbitrary code via a
crafted stereo stream in a media file.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-3951?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ffmpeg | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Fixed 4:0.5.9-0ubuntu0.10.04.1 |
| 8.04 LTS hardy | Ignored end of life |
| ffmpeg-extra | 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.04 LTS lucid | Fixed |
| 8.04 LTS hardy | Not in release |
| libav | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Fixed 4:0.7.6-0ubuntu0.11.10.1 |
| 11.04 natty | Fixed 4:0.6.6-0ubuntu0.11.04.1 |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| libav-extra | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Fixed |
| 11.04 natty | Fixed |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-3951?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

ffmpeg-extra in multiverse needs to have matching version
libav-extra is built with tarball produced by libav package
as of 2012-05-29, no fix in ffmpeg 0.5.x

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| ffmpeg | * Upstream:   <http://git.videolan.org/?p=ffmpeg.git;a=commit;h=ce7aee9b733134649a6ce2fa743e51733f33e67e> |
| libav | * Upstream:   <http://git.libav.org/?p=libav.git;a=commit;h=ce7aee9b733134649a6ce2fa743e51733f33e67e> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3951)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-3951)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-3951)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-3951)

### Related Ubuntu Security Notices (USN)

+ [USN-1478-1](https://usn.ubuntu.com/USN-1478-1)
+ Libav vulnerabilities
+ 18 June 2012

+ [USN-1479-1](https://usn.ubuntu.com/USN-1479-1)
+ FFmpeg vulnerabilities
+ 18 June 2012

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-3951>
