Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3062

Опубликовано: 16 июн. 2016
Источник: debian
EPSS Низкий

Описание

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libavremovedpackage
ffmpegfixed7:2.4.1-1package

Примечания

  • https://git.libav.org/?p=libav.git;a=commit;h=7e01d48cfd168c3dfc663f03a3b6a98e0ecba328

  • https://git.libav.org/?p=libav.git;a=commit;h=5fdcbc4a7cd81114a9f47bcb3040ca510bd6360d (11.7)

  • https://bugzilla.libav.org/show_bug.cgi?id=929

  • https://github.com/FFmpeg/FFmpeg/commit/689e59b7ffed34eba6159dcc78e87133862e3746 (n0.11)

EPSS

Процентиль: 85%
0.02512
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

CVSS3: 8.8
nvd
больше 9 лет назад

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

CVSS3: 8.8
github
больше 3 лет назад

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

suse-cvrf
больше 9 лет назад

Security update for libav

EPSS

Процентиль: 85%
0.02512
Низкий