CVE-2011-3936
Last modified
CVE-2011-3936 is a vulnerability of currently unknown severity. The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.. EPSS estimates a 2.54% chance of exploitation in the next 30 days.
Description
The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | 0.7 |
| Ffmpeg | Ffmpeg | 0.7.1 |
| Ffmpeg | Ffmpeg | 0.7.2 |
| Ffmpeg | Ffmpeg | 0.7.3 |
| Ffmpeg | Ffmpeg | 0.7.6 |
| Ffmpeg | Ffmpeg | 0.7.7 |
| Ffmpeg | Ffmpeg | 0.7.8 |
| Ffmpeg | Ffmpeg | 0.7.9 |
| Ffmpeg | Ffmpeg | 0.7.11 |
| Ffmpeg | Ffmpeg | 0.7.12 |
| Ffmpeg | Ffmpeg | 0.8.0 |
| Ffmpeg | Ffmpeg | 0.8.1 |
| Ffmpeg | Ffmpeg | 0.8.2 |
| Ffmpeg | Ffmpeg | 0.8.5 |
| Ffmpeg | Ffmpeg | 0.8.6 |
| Ffmpeg | Ffmpeg | 0.8.7 |
| Ffmpeg | Ffmpeg | 0.8.8 |
| Ffmpeg | Ffmpeg | 0.8.10 |
| Libav | Libav | 0.5 |
| Libav | Libav | 0.5.1 |
| Libav | Libav | 0.5.2 |
| Libav | Libav | 0.5.3 |
| Libav | Libav | 0.5.4 |
| Libav | Libav | 0.5.5 |
| Libav | Libav | 0.5.6 |
| Libav | Libav | 0.5.7 |
| Libav | Libav | 0.6 |
| Libav | Libav | 0.6.1 |
| Libav | Libav | 0.6.2 |
| Libav | Libav | 0.6.3 |
| Libav | Libav | 0.6.4 |
| Libav | Libav | 0.6.5 |
| Libav | Libav | 0.7 |
| Libav | Libav | 0.7.1 |
| Libav | Libav | 0.7.2 |
| Libav | Libav | 0.7.3 |
| Libav | Libav | 0.7.4 |
| Libav | Libav | 0.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-3936?
How severe is CVE-2011-3936?
How do I fix CVE-2011-3936?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-3926Heap-based buffer overflow in the tree builder in Google Chr…
- CVE-2011-3927Skia, as used in Google Chrome before 16.0.912.77, does not …
- CVE-2011-3928Use-after-free vulnerability in Google Chrome before 16.0.91…
- CVE-2011-3929The avpriv_dv_produce_packet function in libavcodec in FFmpe…
- CVE-2011-3934Double free vulnerability in the vp3_update_thread_context f…
- CVE-2011-3935The codec_get_buffer function in ffmpeg.c in FFmpeg before 0…
- CVE-2011-3937The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x befor…
- CVE-2011-3940nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8…
- CVE-2011-3941The decode_mb function in libavcodec/error_resilience.c in F…
- CVE-2011-3944The smacker_decode_header_tree function in libavcodec/smacke…
- CVE-2011-3945The decode_frame function in the KVG1 decoder (kgv1dec.c) in…
- CVE-2011-3946The ff_h264_decode_sei function in libavcodec/h264_sei.c in …
Are you affected by CVE-2011-3936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
