Vulnerability Name:

CVE-2011-1931 (CCN-67118)

Assigned:2011-04-27
Published:2011-04-27
Updated:2011-09-22
Summary:sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before 0.6.3 and libav through 0.6.2, as used in VideoLAN VLC media player 1.1.9 and earlier and other products, performs a write operation outside the bounds of an unspecified array, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a malformed AMV file.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Wed Apr 27 2011 - 08:14:52 CDT
NGS00068 Patch Notification: LibAVCodec AMV Out of Array Write

Source: CONFIRM
Type: Patch
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=624339

Source: MITRE
Type: CNA
CVE-2011-1931

Source: CCN
Type: ffmpeg.org GIT Repository
git.ffmpeg.org Git - ffmpeg/commitdiff

Source: CONFIRM
Type: Patch
http://git.videolan.org/?p=ffmpeg.git;a=commit;h=89f903b3d5ec38c9c5d90fba7e626fa0eda61a32

Source: CCN
Type: SA44378
FFmpeg Two Vulnerabilities

Source: SREASON
Type: UNKNOWN
8299

Source: CCN
Type: FFmpeg Web site
FFmpeg

Source: CCN
Type: OSVDB ID: 72577
FFmpeg LibAVCodec Sunplus JPEG Decoder AMV File Handling Arbitrary Code Execution

Source: BUGTRAQ
Type: UNKNOWN
20110427 NGS00068 Patch Notification: LibAVCodec AMV Out of Array Write

Source: BID
Type: UNKNOWN
47602

Source: CCN
Type: BID-47602
FFmpeg libavcodec 'sp5xdec.c' '.amv' File Memory Corruption Vulnerability

Source: CCN
Type: VideoLAN Web site
VideoLAN: Free Multimedia Solutions

Source: XF
Type: UNKNOWN
ffmpeg-libavcodec-code-exec(67118)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* (Version <= 0.6.2)
  • OR cpe:/a:ffmpeg:libavcodec:*:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.4.9:pre1:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.6:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:0.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:libav:libav:*:*:*:*:*:*:*:* (Version <= 0.6.2)
  • AND
  • cpe:/a:videolan:vlc_media_player:0.1.99b:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.1.99e:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.1.99f:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.1.99g:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.1.99h:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.1.99i:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.60:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.61:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.62:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.63:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.70:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.71:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.72:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.73:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.80:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.81:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.82:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.83:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.90:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.91:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.2.92:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.8.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.8a:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.9:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:0.9.10:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:*:*:*:*:*:*:*:* (Version <= 1.1.9)

  • Configuration CCN 1:
  • cpe:/a:videolan:vlc_media_player:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:videolan:vlc_media_player:1.1.9:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:21095
    P
    USN-1209-2 -- libav vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:21194
    P
    USN-1209-1 -- ffmpeg vulnerabilities
    2014-06-30
    BACK
    ffmpeg ffmpeg 0.3
    ffmpeg ffmpeg 0.3.1
    ffmpeg ffmpeg 0.3.2
    ffmpeg ffmpeg 0.3.3
    ffmpeg ffmpeg 0.3.4
    ffmpeg ffmpeg 0.4.0
    ffmpeg ffmpeg 0.4.2
    ffmpeg ffmpeg 0.4.3
    ffmpeg ffmpeg 0.4.4
    ffmpeg ffmpeg 0.4.5
    ffmpeg ffmpeg 0.4.6
    ffmpeg ffmpeg 0.4.7
    ffmpeg ffmpeg 0.4.8
    ffmpeg ffmpeg 0.4.9 pre1
    ffmpeg ffmpeg 0.5
    ffmpeg ffmpeg 0.5.1
    ffmpeg ffmpeg 0.5.2
    ffmpeg ffmpeg 0.5.3
    ffmpeg ffmpeg 0.5.4
    ffmpeg ffmpeg 0.6
    ffmpeg ffmpeg 0.6.1
    ffmpeg ffmpeg *
    ffmpeg libavcodec *
    libav libav 0.3
    libav libav 0.3.1
    libav libav 0.3.2
    libav libav 0.3.3
    libav libav 0.3.4
    libav libav 0.4.0
    libav libav 0.4.1
    libav libav 0.4.2
    libav libav 0.4.3
    libav libav 0.4.4
    libav libav 0.4.5
    libav libav 0.4.6
    libav libav 0.4.7
    libav libav 0.4.8
    libav libav 0.4.9 pre1
    libav libav 0.5
    libav libav 0.5.4
    libav libav 0.6
    libav libav 0.6.1
    libav libav *
    videolan vlc media player 0.1.99b
    videolan vlc media player 0.1.99e
    videolan vlc media player 0.1.99f
    videolan vlc media player 0.1.99g
    videolan vlc media player 0.1.99h
    videolan vlc media player 0.1.99i
    videolan vlc media player 0.2.0
    videolan vlc media player 0.2.60
    videolan vlc media player 0.2.61
    videolan vlc media player 0.2.62
    videolan vlc media player 0.2.63
    videolan vlc media player 0.2.70
    videolan vlc media player 0.2.71
    videolan vlc media player 0.2.72
    videolan vlc media player 0.2.73
    videolan vlc media player 0.2.80
    videolan vlc media player 0.2.81
    videolan vlc media player 0.2.82
    videolan vlc media player 0.2.83
    videolan vlc media player 0.2.90
    videolan vlc media player 0.2.91
    videolan vlc media player 0.2.92
    videolan vlc media player 0.3.0
    videolan vlc media player 0.3.1
    videolan vlc media player 0.4.0
    videolan vlc media player 0.4.1
    videolan vlc media player 0.4.2
    videolan vlc media player 0.4.3
    videolan vlc media player 0.4.4
    videolan vlc media player 0.4.5
    videolan vlc media player 0.4.6
    videolan vlc media player 0.5.0
    videolan vlc media player 0.5.1
    videolan vlc media player 0.5.2
    videolan vlc media player 0.5.3
    videolan vlc media player 0.6.0
    videolan vlc media player 0.6.1
    videolan vlc media player 0.6.2
    videolan vlc media player 0.7.0
    videolan vlc media player 0.7.2
    videolan vlc media player 0.8.0
    videolan vlc media player 0.8.1
    videolan vlc media player 0.8.2
    videolan vlc media player 0.8.4
    videolan vlc media player 0.8.5
    videolan vlc media player 0.8.6
    videolan vlc media player 0.9.2
    videolan vlc media player 0.9.3
    videolan vlc media player 0.9.4
    videolan vlc media player 0.9.5
    videolan vlc media player 0.9.6
    videolan vlc media player 0.9.8a
    videolan vlc media player 0.9.9
    videolan vlc media player 0.9.10
    videolan vlc media player 1.0.0
    videolan vlc media player 1.0.1
    videolan vlc media player 1.0.2
    videolan vlc media player 1.0.3
    videolan vlc media player 1.0.4
    videolan vlc media player 1.0.5
    videolan vlc media player 1.0.6
    videolan vlc media player 1.1.0
    videolan vlc media player 1.1.1
    videolan vlc media player 1.1.2
    videolan vlc media player 1.1.3
    videolan vlc media player 1.1.4
    videolan vlc media player 1.1.4.1
    videolan vlc media player 1.1.5
    videolan vlc media player 1.1.6
    videolan vlc media player 1.1.7
    videolan vlc media player 1.1.8
    videolan vlc media player *
    videolan vlc media player 1.0.0
    videolan vlc media player 1.0.1
    ffmpeg ffmpeg 0.5
    videolan vlc media player 1.0.3
    videolan vlc media player 1.0.2
    videolan vlc media player 1.0.5
    videolan vlc media player 1.0.6
    videolan vlc media player 1.1.3
    ffmpeg ffmpeg 0.6
    videolan vlc media player 1.1.4
    videolan vlc media player 1.1.2
    videolan vlc media player 1.1.1
    videolan vlc media player 1.1.0
    videolan vlc media player 1.0.4
    videolan vlc media player 1.1.5
    videolan vlc media player 1.1.6
    videolan vlc media player 1.1.7
    ffmpeg ffmpeg 0.5.3
    videolan vlc media player 1.1.8
    videolan vlc media player 1.1.9