CVE-2011-4031Integer Underflow (Wrap or Wraparound) in Ffmpeg

Severity
6.8MEDIUMNVD
EPSS
2.8%
top 13.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 9
Latest updateMay 13

Description

Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDffmpeg/ffmpeg< 0.8.3
debiandebian/ffmpeg

Patches

🔴Vulnerability Details

1
GHSA
GHSA-4cpw-52r2-x798: Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf2022-05-13

📋Vendor Advisories

2
Ubuntu
Libav vulnerabilities2012-06-18
Debian
CVE-2011-4031: ffmpeg - Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf....2011