CVE-2011-4031
Publication date 9 May 2012
Last updated 24 July 2024
Ubuntu priority
Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | ||
ffmpeg-extra | ||
libav | ||
libav-extra | ||
Notes
mdeslaur
ffmpeg-extra in multiverse needs to have matching version libav-extra is built with tarball produced by libav package code not present in ffmpeg 0.5.x libav upstream says 0.6.x is not affected
Patch details
Package | Patch details |
---|---|
ffmpeg | |
libav |
References
Related Ubuntu Security Notices (USN)
- USN-1478-1
- Libav vulnerabilities
- 18 June 2012