CVE-2011-3504
published 2011-09-29CVE-2011-3504: The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.85%
92.4th percentile
The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.8.0 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-01-17·CVSS 9.3
CVE-2011-3504 [CRITICAL] Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
Steve Manzuik discovered that Libav incorrectly handled certain malformed
Matroska files. If a user were tricked into opening a crafted Matroska
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. This issue only affected Ubuntu 11.04. (CVE-2011-3504)
Phillip Langlois discovered that Libav incorrectly handled certain
malformed QDM2 streams. If a user were tricked into opening a crafted QDM2
stream file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking t
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2012-01-05·CVSS 9.3
CVE-2011-4353 [CRITICAL] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash or run programs as your login if it
opened a specially crafted file.
Steve Manzuik discovered that FFmpeg incorrectly handled certain malformed
Matroska files. If a user were tricked into opening a crafted Matroska
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2011-3504)
Phillip Langlois discovered that FFmpeg incorrectly handled certain
malformed QDM2 streams. If a user were tricked into opening a crafted QDM2
stream file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2011-4351)
Philli
Debian
CVE-2011-3504: ffmpeg - The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate me...
vendor_debian·2011·CVSS 9.3
CVE-2011-3504 [CRITICAL] CVE-2011-3504: ffmpeg - The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate me...
The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-78h7-gxcg-7x5r: The Matroska format decoder in FFmpeg before 0
ghsa_unreviewed·2022-05-14
CVE-2011-3504 [HIGH] CWE-94 GHSA-78h7-gxcg-7x5r: The Matroska format decoder in FFmpeg before 0
The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.
OSV
CVE-2011-3504: The Matroska format decoder in FFmpeg before 0
osv·2011-09-29·CVSS 9.3
CVE-2011-3504 [CRITICAL] CVE-2011-3504: The Matroska format decoder in FFmpeg before 0
The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/45532http://technet.microsoft.com/en-us/security/msvr/msvr11-011http://ubuntu.com/usn/usn-1320-1http://ubuntu.com/usn/usn-1333-1http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changeloghttp://www.ffmpeg.org/releases/ffmpeg-0.8.4.changeloghttp://www.mandriva.com/security/advisories?name=MDVSA-2012:074http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076http://www.osvdb.org/75621http://secunia.com/advisories/45532http://technet.microsoft.com/en-us/security/msvr/msvr11-011http://ubuntu.com/usn/usn-1320-1http://ubuntu.com/usn/usn-1333-1http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changeloghttp://www.ffmpeg.org/releases/ffmpeg-0.8.4.changeloghttp://www.mandriva.com/security/advisories?name=MDVSA-2012:074http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076http://www.osvdb.org/75621
2011-09-29
Published