CVE-2011-3947

Buffer overflow in mjpegbdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MJPEG-B file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ffmpeg:ffmpeg:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.7.6:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.7.7:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.7.8:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.7.9:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.7.11:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ffmpeg:ffmpeg:0.8.5:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.8.7:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.8.8:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:0.8.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:libav:libav:0.5:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.3:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.4:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.5:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.6:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.5.7:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:libav:libav:0.6:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.6.3:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.6.5:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:libav:libav:0.7:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.7.4:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:libav:libav:0.8:*:*:*:*:*:*:*
cpe:2.3:a:libav:libav:0.8:beta2:*:*:*:*:*:*

History

07 Nov 2023, 02:09

Type Values Removed Values Added
References
  • {'url': 'http://git.videolan.org/?p=ffmpeg.git;a=commit;h=b57d262412204e54a7ef8fa1b23ff4dcede622e5', 'name': 'http://git.videolan.org/?p=ffmpeg.git;a=commit;h=b57d262412204e54a7ef8fa1b23ff4dcede622e5', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'http://git.libav.org/?p=libav.git;a=commit;h=b57d262412204e54a7ef8fa1b23ff4dcede622e5', 'name': 'http://git.libav.org/?p=libav.git;a=commit;h=b57d262412204e54a7ef8fa1b23ff4dcede622e5', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://git.libav.org/?p=libav.git%3Ba=commit%3Bh=b57d262412204e54a7ef8fa1b23ff4dcede622e5 -
  • () http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=b57d262412204e54a7ef8fa1b23ff4dcede622e5 -
References (DEBIAN) http://www.debian.org/security/2012/dsa-2471 - () http://www.debian.org/security/2012/dsa-2471 -
References (CONFIRM) http://ffmpeg.org/ - Vendor Advisory () http://ffmpeg.org/ -
References (CONFIRM) http://libav.org/ - Vendor Advisory () http://libav.org/ -
References (SECUNIA) http://secunia.com/advisories/49089 - () http://secunia.com/advisories/49089 -
References (UBUNTU) http://www.ubuntu.com/usn/USN-1479-1 - () http://www.ubuntu.com/usn/USN-1479-1 -

Information

Published : 2012-08-20 18:55

Updated : 2023-12-10 11:16


NVD link : CVE-2011-3947

Mitre link : CVE-2011-3947

CVE.ORG link : CVE-2011-3947


JSON object : View

Products Affected

libav

  • libav

ffmpeg

  • ffmpeg
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer