CVE-2011-3951
Last modified
CVE-2011-3951 is a vulnerability of currently unknown severity. The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted stereo stream in a media file.. EPSS estimates a 3.11% chance of exploitation in the next 30 days.
Description
The dpcm_decode_frame function in dpcm.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted stereo stream in a media file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | <= 0.9.1 |
| Ffmpeg | Ffmpeg | 0.7.1 |
| Ffmpeg | Ffmpeg | 0.7.2 |
| Ffmpeg | Ffmpeg | 0.7.7 |
| Ffmpeg | Ffmpeg | 0.7.8 |
| Ffmpeg | Ffmpeg | 0.7.9 |
| Ffmpeg | Ffmpeg | 0.7.11 |
| Ffmpeg | Ffmpeg | 0.7.12 |
| Ffmpeg | Ffmpeg | 0.8.5 |
| Ffmpeg | Ffmpeg | 0.8.6 |
| Ffmpeg | Ffmpeg | 0.8.7 |
| Ffmpeg | Ffmpeg | 0.8.8 |
| Ffmpeg | Ffmpeg | 0.8.10 |
| Ffmpeg | Ffmpeg | 0.8.11 |
| Ffmpeg | Ffmpeg | 0.9 |
| Libav | Libav | 0.5 |
| Libav | Libav | 0.5.1 |
| Libav | Libav | 0.5.2 |
| Libav | Libav | 0.5.3 |
| Libav | Libav | 0.5.4 |
| Libav | Libav | 0.5.5 |
| Libav | Libav | 0.5.6 |
| Libav | Libav | 0.5.7 |
| Libav | Libav | 0.6 |
| Libav | Libav | 0.6.1 |
| Libav | Libav | 0.6.2 |
| Libav | Libav | 0.6.3 |
| Libav | Libav | 0.6.4 |
| Libav | Libav | 0.6.5 |
| Libav | Libav | 0.7 |
| Libav | Libav | 0.7.1 |
| Libav | Libav | 0.7.2 |
| Libav | Libav | 0.7.3 |
| Libav | Libav | 0.7.4 |
| Libav | Libav | 0.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-3951?
How severe is CVE-2011-3951?
How do I fix CVE-2011-3951?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-3944The smacker_decode_header_tree function in libavcodec/smacke…
- CVE-2011-3945The decode_frame function in the KVG1 decoder (kgv1dec.c) in…
- CVE-2011-3946The ff_h264_decode_sei function in libavcodec/h264_sei.c in …
- CVE-2011-3947Buffer overflow in mjpegbdec.c in libavcodec in FFmpeg 0.7.x…
- CVE-2011-3949The dirac_unpack_idwt_params function in libavcodec/diracdec…
- CVE-2011-3950The dirac_decode_data_unit function in libavcodec/diracdec.c…
- CVE-2011-3952The decode_init function in kmvc.c in libavcodec in FFmpeg b…
- CVE-2011-3953Google Chrome before 17.0.963.46 does not prevent monitoring…
- CVE-2011-3954Google Chrome before 17.0.963.46 allows remote attackers to …
- CVE-2011-3955Google Chrome before 17.0.963.46 allows remote attackers to …
- CVE-2011-3956The extension implementation in Google Chrome before 17.0.96…
- CVE-2011-3957Use-after-free vulnerability in the garbage-collection funct…
Are you affected by CVE-2011-3951?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
