CVE-2011-2160

Publication date 20 May 2011

Last updated 24 July 2024


Ubuntu priority

The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.

Read the notes from the security team

Status

Package Ubuntu Release Status
ffmpeg 11.04 natty Not in release
10.10 maverick
Not affected
10.04 LTS lucid
Fixed 4:0.5.1-1ubuntu1.1
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Ignored end of life
ffmpeg-extra 11.04 natty Not in release
10.10 maverick
Not affected
10.04 LTS lucid
Fixed 4:0.5.1-1ubuntu1.1
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release
libav 11.04 natty
Not affected
10.10 maverick Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release
libav-extra 11.04 natty
Not affected
10.10 maverick Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

ffmpeg-extra in multiverse needs to have matching version we already fixed this as part of CVE-2011-0723

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ffmpeg