CVE-2011-3952 Information
Feb 14, 2021
cve
Description
The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9 0.6.x before 0.6.6 0.7.x before 0.7.6 and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large palette size in a KMVC encoded file.
Reference
http://ffmpeg.org/ http://git.libav.org/?p=libav.git;a=commit;h=386741f887714d3e46c9e8fe577e326a7964037b http://libav.org/ http://www.debian.org/security/2012/dsa-2494 http://www.ubuntu.com/usn/USN-1479-1
Share on: