CVE-2011-0723
published 2011-05-20CVE-2011-0723: FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.43%
90.4th percentile
FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.5.3 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2011-04-04·CVSS 6.8
CVE-2010-4704 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to run programs as your login if it opened a specially
crafted file.
Cesar Bernardini and Felipe Andres Manzano discovered that FFmpeg
incorrectly handled certain malformed flic files. If a user were tricked
into opening a crafted flic file, an attacker could cause a denial of
service via application crash, or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3429)
Dan Rosenberg discovered that FFmpeg incorrectly handled certain malformed
wmv files. If a user were tricked into opening a crafted wmv file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileg
Debian
CVE-2011-0723: ffmpeg - FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to ...
vendor_debian·2011·CVSS 6.8
CVE-2011-0723 [MEDIUM] CVE-2011-0723: ffmpeg - FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to ...
FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
Debian
CVE-2011-2160: ffmpeg - The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and o...
vendor_debian·2011·CVSS 6.8
CVE-2011-2160 [MEDIUM] CVE-2011-2160: ffmpeg - The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and o...
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-xcpc-jvcx-3fxc: The VC-1 decoding functionality in FFmpeg before 0
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-2160 [MEDIUM] CWE-20 GHSA-xcpc-jvcx-3fxc: The VC-1 decoding functionality in FFmpeg before 0
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
GHSA
GHSA-rp5c-q9p5-vm9v: FFmpeg 0
ghsa_unreviewed·2022-05-17
CVE-2011-0723 [MEDIUM] GHSA-rp5c-q9p5-vm9v: FFmpeg 0
FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file.
OSV
CVE-2011-2160: The VC-1 decoding functionality in FFmpeg before 0
osv·2011-05-20·CVSS 6.8
CVE-2011-2160 [MEDIUM] CVE-2011-2160: The VC-1 decoding functionality in FFmpeg before 0
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
OSV
CVE-2011-0723: FFmpeg 0
osv·2011-05-20·CVSS 6.8
CVE-2011-0723 [MEDIUM] CVE-2011-0723: FFmpeg 0
FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.mplayerhq.hu/http://www.debian.org/security/2011/dsa-2306http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:062http://www.mandriva.com/security/advisories?name=MDVSA-2011:089http://www.mandriva.com/security/advisories?name=MDVSA-2011:112http://www.mandriva.com/security/advisories?name=MDVSA-2011:114http://www.securityfocus.com/bid/47151http://www.ubuntu.com/usn/usn-1104-1/http://www.vupen.com/english/advisories/2011/1241http://ffmpeg.mplayerhq.hu/http://www.debian.org/security/2011/dsa-2306http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:062http://www.mandriva.com/security/advisories?name=MDVSA-2011:089http://www.mandriva.com/security/advisories?name=MDVSA-2011:112http://www.mandriva.com/security/advisories?name=MDVSA-2011:114http://www.securityfocus.com/bid/47151http://www.ubuntu.com/usn/usn-1104-1/http://www.vupen.com/english/advisories/2011/1241
2011-05-20
Published