CVE-2011-0722Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
6.8MEDIUMNVD
EPSS
0.9%
top 24.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 17

Description

FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a malformed RealMedia file.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 7:2.4.1-1 (bookworm)
Debianffmpeg/ffmpeg< 7:2.4.1-1+3
NVDffmpeg/ffmpeg0.5.3+17

🔴Vulnerability Details

2
GHSA
GHSA-mv9w-pp72-p7j5: FFmpeg before 02022-05-17
OSV
CVE-2011-0722: FFmpeg before 02011-05-20

📋Vendor Advisories

2
Ubuntu
FFmpeg vulnerabilities2011-04-04
Debian
CVE-2011-0722: ffmpeg - FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attack...2011