PublicDateAtUSN: 2012-05-09 Candidate: CVE-2011-4031 PublicDate: 2012-05-09 10:33:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4031 http://technet.microsoft.com/en-us/security/msvr/msvr11-012 https://ubuntu.com/security/notices/USN-1478-1 Description: Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet. Ubuntu-Description: Notes: mdeslaur> ffmpeg-extra in multiverse needs to have matching version mdeslaur> libav-extra is built with tarball produced by libav package mdeslaur> code not present in ffmpeg 0.5.x mdeslaur> libav upstream says 0.6.x is not affected Bugs: Priority: medium Discovered-by: Jeong Wook Oh Assigned-to: CVSS: Patches_ffmpeg: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=ba9a7e0d71bd34f8b89ae99322b62a310be163a6 upstream_ffmpeg: released (0.8.3) hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: not-affected (code not present) natty_ffmpeg: DNE oneiric_ffmpeg: DNE precise_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: not-affected (code not present) natty_ffmpeg-extra: DNE oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream: http://git.libav.org/?p=libav.git;a=commit;h=5ea091fb5a12dc0210b8efdf30b573b87e21652b upstream_libav: released (0.8.0,0.7.6) hardy_libav: DNE lucid_libav: DNE natty_libav: not-affected oneiric_libav: released (4:0.7.6-0ubuntu0.11.10.1) precise_libav: not-affected (4:0.8.1-0ubuntu1) devel_libav: not-affected (4:0.8.1-0ubuntu2) Patches_libav-extra: upstream_libav-extra: needs-triage hardy_libav-extra: DNE lucid_libav-extra: DNE natty_libav-extra: not-affected oneiric_libav-extra: released precise_libav-extra: not-affected (4:0.8.1ubuntu1) devel_libav-extra: not-affected (4:0.8.1ubuntu1)