CVE-2011-3945 (retired)

Priority
Description
The decode_frame function in the KVG1 decoder (kgv1dec.c) in libavcodec in
FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x
before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before
0.8.1, allows remote attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a crafted media file.
Notes
 mdeslaur> ffmpeg-extra in multiverse needs to have matching version
 mdeslaur> libav-extra is built with tarball produced by libav package
 mdeslaur> code not present in ffmpeg 0.5.x
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Patches:
Upstream:http://git.videolan.org/?p=ffmpeg.git;a=commit;h=807a045ab7f51993a2c1b3116016cbbd4f3d20d6
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Package
Source: libav (LP Ubuntu Debian)
Upstream:released (0.6.6,0.7.5,0.8.1)
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (4:0.8.1-0ubuntu2)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (4:0.8.1ubuntu1)
More Information

Updated: 2019-03-26 11:58:52 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)