CVE-2011-4364
published 2012-08-20CVE-2011-4364: Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.02%
91.4th percentile
Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2012-01-17·CVSS 9.3
CVE-2011-3504 [CRITICAL] Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
Steve Manzuik discovered that Libav incorrectly handled certain malformed
Matroska files. If a user were tricked into opening a crafted Matroska
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. This issue only affected Ubuntu 11.04. (CVE-2011-3504)
Phillip Langlois discovered that Libav incorrectly handled certain
malformed QDM2 streams. If a user were tricked into opening a crafted QDM2
stream file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking t
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2012-01-05·CVSS 9.3
CVE-2011-4353 [CRITICAL] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash or run programs as your login if it
opened a specially crafted file.
Steve Manzuik discovered that FFmpeg incorrectly handled certain malformed
Matroska files. If a user were tricked into opening a crafted Matroska
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2011-3504)
Phillip Langlois discovered that FFmpeg incorrectly handled certain
malformed QDM2 streams. If a user were tricked into opening a crafted QDM2
stream file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2011-4351)
Philli
Debian
CVE-2011-4364: ffmpeg - Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0...
vendor_debian·2011·CVSS 6.8
CVE-2011-4364 [MEDIUM] CVE-2011-4364: ffmpeg - Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0...
Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-m58j-4g2v-78p2: Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0
ghsa_unreviewed·2022-05-17
CVE-2011-4364 [MEDIUM] CWE-119 GHSA-m58j-4g2v-78p2: Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0
Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.
OSV
CVE-2011-4364: Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0
osv·2012-08-20·CVSS 6.8
CVE-2011-4364 [MEDIUM] CVE-2011-4364: Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0
Buffer overflow in the Sierra VMD decoder in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9 and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VMD file, related to corrupted streams.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.org/http://git.libav.org/?p=libav.git%3Ba=commit%3Bh=c0cbe36b18ab3eb13a53fe684ec1f63a00df2c86http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=c0cbe36b18ab3eb13a53fe684ec1f63a00df2c86http://libav.org/http://libav.org/releases/libav-0.5.6.changeloghttp://libav.org/releases/libav-0.6.4.changeloghttp://libav.org/releases/libav-0.7.3.changeloghttp://ubuntu.com/usn/usn-1320-1http://ubuntu.com/usn/usn-1333-1http://www.mandriva.com/security/advisories?name=MDVSA-2012:074http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076http://ffmpeg.org/http://git.libav.org/?p=libav.git%3Ba=commit%3Bh=c0cbe36b18ab3eb13a53fe684ec1f63a00df2c86http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=c0cbe36b18ab3eb13a53fe684ec1f63a00df2c86http://libav.org/http://libav.org/releases/libav-0.5.6.changeloghttp://libav.org/releases/libav-0.6.4.changeloghttp://libav.org/releases/libav-0.7.3.changeloghttp://ubuntu.com/usn/usn-1320-1http://ubuntu.com/usn/usn-1333-1http://www.mandriva.com/security/advisories?name=MDVSA-2012:074http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076
2012-08-20
Published