CVE-2011-3974
published 2011-10-02CVE-2011-3974: Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.50%
83.0th percentile
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.7.3 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-3974: ffmpeg - Integer signedness error in the decode_residual_inter function in cavsdec.c in l...
vendor_debian·2011·CVSS 6.8
CVE-2011-3974 [MEDIUM] CVE-2011-3974: ffmpeg - Integer signedness error in the decode_residual_inter function in cavsdec.c in l...
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-7678-79q4-rmhw: Integer signedness error in the decode_residual_inter function in cavsdec
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-3974 [MEDIUM] GHSA-7678-79q4-rmhw: Integer signedness error in the decode_residual_inter function in cavsdec
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
OSV
CVE-2011-3974: Integer signedness error in the decode_residual_inter function in cavsdec
osv·2011-10-02·CVSS 6.8
CVE-2011-3974 [MEDIUM] CVE-2011-3974: Integer signedness error in the decode_residual_inter function in cavsdec
Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=bd968d260aef322fb32e254a3de0d2036c57bd56http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changeloghttp://www.ffmpeg.org/releases/ffmpeg-0.8.4.changeloghttp://www.mandriva.com/security/advisories?name=MDVSA-2012:074http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=bd968d260aef322fb32e254a3de0d2036c57bd56http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changeloghttp://www.ffmpeg.org/releases/ffmpeg-0.8.4.changeloghttp://www.mandriva.com/security/advisories?name=MDVSA-2012:074http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076
2011-10-02
Published