LWN.net Logo

ffmpeg: code execution

Package(s):ffmpeg CVE #(s):CVE-2011-3973 CVE-2011-3974 CVE-2011-3504
Created:November 8, 2011 Updated:August 30, 2012
Description: The Chinese AVS video decoder in ffmpeg suffers from multiple memory corruption and application crash errors (CVE-2011-3973/CVE-2011-3974). There is also a vulnerability in the Matroska decoder (CVE-2011-3504) that can enable code execution via a malicious media file.
Alerts:
Debian DSA-2336-1 2011-11-07
Ubuntu USN-1320-1 2012-01-05
Ubuntu USN-1333-1 2012-01-17
Mandriva MDVSA-2012:074 2012-05-14
Mandriva MDVSA-2012:075 2012-05-15
Mandriva MDVSA-2012:076 2012-05-15
Mandriva MDVSA-2012:074-1 2012-08-30
Mandriva MDVSA-2012:148 2012-08-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds