CVE-2011-3362
published 2011-10-02CVE-2011-3362: Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.41%
87.6th percentile
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.7.3 | — |
| ffmpeg | ffmpeg | <= 0.7.2 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2011-09-19·CVSS 7.5
CVE-2011-2161 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to run programs as your login if it opened a specially
crafted file.
It was discovered that FFmpeg incorrectly handled certain malformed ogg
files. If a user were tricked into opening a crafted ogg file, an attacker
could cause a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the program. This
issue only affected Ubuntu 10.10. (CVE-2011-1196)
It was discovered that FFmpeg incorrectly handled certain malformed AMV
files. If a user were tricked into opening a crafted AMV file, an attacker
could cause a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the program. This
issue only affected Ubuntu
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2011-09-19·CVSS 7.5
CVE-2011-1196 [HIGH] Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to run programs as your login if it opened a specially
crafted file.
It was discovered that Libav incorrectly handled certain malformed ogg
files. If a user were tricked into opening a crafted ogg file, an attacker
could cause a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2011-1196)
It was discovered that Libav incorrectly handled certain malformed AMV
files. If a user were tricked into opening a crafted AMV file, an attacker
could cause a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2011-1931)
Emmanouel Kellinis discovered that Libav incorrectly hand
Debian
CVE-2011-3974: ffmpeg - Integer signedness error in the decode_residual_inter function in cavsdec.c in l...
vendor_debian·2011·CVSS 6.8
CVE-2011-3974 [MEDIUM] CVE-2011-3974: ffmpeg - Integer signedness error in the decode_residual_inter function in cavsdec.c in l...
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
Debian
CVE-2011-3973: ffmpeg - cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows rem...
vendor_debian·2011·CVSS 6.8
CVE-2011-3973 [MEDIUM] CVE-2011-3973: ffmpeg - cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows rem...
cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
Debian
CVE-2011-3362: ffmpeg - Integer signedness error in the decode_residual_block function in cavsdec.c in l...
vendor_debian·2011·CVSS 6.8
CVE-2011-3362 [MEDIUM] CVE-2011-3362: ffmpeg - Integer signedness error in the decode_residual_block function in cavsdec.c in l...
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-v2j8-vr47-x5g5: cavsdec
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-3973 [MEDIUM] GHSA-v2j8-vr47-x5g5: cavsdec
cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362.
GHSA
GHSA-47gg-42gp-g49j: Integer signedness error in the decode_residual_block function in cavsdec
ghsa_unreviewed·2022-05-17
CVE-2011-3362 [MEDIUM] GHSA-47gg-42gp-g49j: Integer signedness error in the decode_residual_block function in cavsdec
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
GHSA
GHSA-7678-79q4-rmhw: Integer signedness error in the decode_residual_inter function in cavsdec
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-3974 [MEDIUM] GHSA-7678-79q4-rmhw: Integer signedness error in the decode_residual_inter function in cavsdec
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
OSV
CVE-2011-3974: Integer signedness error in the decode_residual_inter function in cavsdec
osv·2011-10-02·CVSS 6.8
CVE-2011-3974 [MEDIUM] CVE-2011-3974: Integer signedness error in the decode_residual_inter function in cavsdec
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
OSV
CVE-2011-3362: Integer signedness error in the decode_residual_block function in cavsdec
osv·2011-10-02·CVSS 6.8
CVE-2011-3362 [MEDIUM] CVE-2011-3362: Integer signedness error in the decode_residual_block function in cavsdec
Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.
OSV
CVE-2011-3973: cavsdec
osv·2011-10-02·CVSS 6.8
CVE-2011-3973 [MEDIUM] CVE-2011-3973: cavsdec
cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=91d5da9321c52e8197fb14046ebb335f3e6ff4a0http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=c5cbda50793e311aa73489d12184ffd6761c9fbfhttp://secunia.com/advisories/45532http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changeloghttp://www.ffmpeg.org/releases/ffmpeg-0.8.4.changeloghttp://www.ocert.org/advisories/ocert-2011-002.htmlhttp://www.openwall.com/lists/oss-security/2011/09/13/4http://www.openwall.com/lists/oss-security/2011/09/14/8http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=91d5da9321c52e8197fb14046ebb335f3e6ff4a0http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=c5cbda50793e311aa73489d12184ffd6761c9fbfhttp://secunia.com/advisories/45532http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changeloghttp://www.ffmpeg.org/releases/ffmpeg-0.8.4.changeloghttp://www.ocert.org/advisories/ocert-2011-002.htmlhttp://www.openwall.com/lists/oss-security/2011/09/13/4http://www.openwall.com/lists/oss-security/2011/09/14/8
2011-10-02
Published