Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2011-3952 | First vendor Publication | 2012-08-20 |
| Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
| Cvss vector : N/A | |||
|---|---|---|---|
| Overall CVSS Score | NA | ||
| Base Score | NA | Environmental Score | NA |
| impact SubScore | NA | Temporal Score | NA |
| Exploitabality Sub Score | NA | ||
| Calculate full CVSS 3.0 Vectors scores | |||
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 6.8 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentication | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
| The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large palette size in a KMVC encoded file. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3952 |
CWE : Common Weakness Enumeration
| % | Id | Name |
|---|---|---|
| 100 % | CWE-20 | Improper Input Validation |
CPE : Common Platform Enumeration
OpenVAS Exploits
| Date | Description |
|---|---|
| 2012-10-22 | Name : Gentoo Security Advisory GLSA 201210-06 (libav) File : nvt/glsa_201210_06.nasl |
| 2012-08-10 | Name : Debian Security Advisory DSA 2494-1 (ffmpeg) File : nvt/deb_2494_1.nasl |
| 2012-06-19 | Name : Ubuntu Update for libav USN-1478-1 File : nvt/gb_ubuntu_USN_1478_1.nasl |
| 2012-06-19 | Name : Ubuntu Update for ffmpeg USN-1479-1 File : nvt/gb_ubuntu_USN_1479_1.nasl |
Nessus® Vulnerability Scanner
| Date | Description |
|---|---|
| 2013-10-27 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201310-12.nasl - Type : ACT_GATHER_INFO |
| 2013-10-27 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201310-13.nasl - Type : ACT_GATHER_INFO |
| 2013-08-21 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_4d087b35099011e3a9f4bcaec565249c.nasl - Type : ACT_GATHER_INFO |
| 2012-10-22 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201210-06.nasl - Type : ACT_GATHER_INFO |
| 2012-06-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2494.nasl - Type : ACT_GATHER_INFO |
| 2012-06-19 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1478-1.nasl - Type : ACT_GATHER_INFO |
| 2012-06-19 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1479-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2024-11-25 11:24:36 |
|
| 2023-11-07 21:46:51 |
|
| 2021-05-05 01:09:25 |
|
| 2021-05-04 12:17:44 |
|
| 2021-04-22 01:21:02 |
|
| 2020-05-23 01:47:12 |
|
| 2020-05-23 00:31:51 |
|
| 2018-10-31 00:20:16 |
|
| 2018-09-15 01:03:51 |
|
| 2016-06-28 18:52:25 |
|
| 2016-04-26 21:10:41 |
|
| 2014-02-17 11:05:47 |
|
| 2013-05-10 23:09:20 |
|








