The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2011-05-20 15:55
Updated : 2011-09-06 20:17
NVD link : CVE-2011-2160
Mitre link : CVE-2011-2160
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
mplayerhq
- mplayer
ffmpeg
- ffmpeg