CVE-2011-3940
EPSS 1.0%Published: 8/20/2012Modified: 4/28/2026
Description
nsvdec.c in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1, allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted NSV file that triggers "use of uninitialized streams."
Affected packages (1)
- Debian/ffmpegfrom 0, < 7:2.4.1-1