CVE-2011-3936 (retired)

Priority
Description
The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12
and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before
0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers
to cause a denial of service (out-of-bounds read and application crash) via
a crafted DV file.
Notes
 mdeslaur> ffmpeg-extra in multiverse needs to have matching version
 mdeslaur> libav-extra is built with tarball produced by libav package
 mdeslaur> see patches for CVE-2011-3929
Package
Upstream:released (0.5.9)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Package
Source: libav (LP Ubuntu Debian)
Upstream:released (0.6.6,0.7.5,0.8.1)
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (4:0.8.1-0ubuntu2)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (4:0.8.1ubuntu1)
More Information

Updated: 2019-03-26 11:58:52 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)