CVE-2011-3504
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
29/09/2011
Last modified:
30/10/2018
Description
The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | 0.8.0 (including) | |
cpe:2.3:a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:ffmpeg:ffmpeg:0.4.9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/45532
- http://technet.microsoft.com/en-us/security/msvr/msvr11-011
- http://ubuntu.com/usn/usn-1320-1
- http://ubuntu.com/usn/usn-1333-1
- http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changelog
- http://www.ffmpeg.org/releases/ffmpeg-0.8.4.changelog
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A074
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A075
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A076
- http://www.osvdb.org/75621