CVE-2011-3952 (retired)

Priority
Description
The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and
in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and
0.8.x before 0.8.1 allows remote attackers to cause a denial of service
(application crash) and possibly execute arbitrary code via a large palette
size in a KMVC encoded file.
Notes
 mdeslaur> ffmpeg-extra in multiverse needs to have matching version
 mdeslaur> libav-extra is built with tarball produced by libav package
 mdeslaur> as of 2012-05-29, doesn't seem to be fixed in libav 0.7
 mdeslaur> as of 2012-05-29, doesn't seem to be fixed in ffmpeg 0.5.x
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Patches:
Upstream:http://git.videolan.org/?p=ffmpeg.git;a=commit;h=386741f887714d3e46c9e8fe577e326a7964037b
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Package
Source: libav (LP Ubuntu Debian)
Upstream:released (0.8.1,0.6.6)
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (4:0.8.1-0ubuntu2)
Patches:
Upstream:http://git.libav.org/?p=libav.git;a=commit;h=386741f887714d3e46c9e8fe577e326a7964037b
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (4:0.8.1ubuntu1)
More Information

Updated: 2019-03-26 11:58:53 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)