CVE-2016-3062

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libav:libav:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-06-16 18:59

Updated : 2024-02-04 18:53


NVD link : CVE-2016-3062

Mitre link : CVE-2016-3062

CVE.ORG link : CVE-2016-3062


JSON object : View

Products Affected

ffmpeg

  • ffmpeg

libav

  • libav

debian

  • debian_linux

opensuse

  • leap
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer