Vulnerability Details CVE-2011-2160
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.2%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2011-2160
-
cpe:2.3:a:ffmpeg:ffmpeg:-
-
cpe:2.3:a:ffmpeg:ffmpeg:0.3
-
cpe:2.3:a:ffmpeg:ffmpeg:0.3.1
-
cpe:2.3:a:ffmpeg:ffmpeg:0.3.2
-
cpe:2.3:a:ffmpeg:ffmpeg:0.3.3
-
cpe:2.3:a:ffmpeg:ffmpeg:0.3.4
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.0
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.2
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.3
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.4
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.5
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.6
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.7
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.8
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.9
-
cpe:2.3:a:ffmpeg:ffmpeg:0.4.9_pre1
-
cpe:2.3:a:ffmpeg:ffmpeg:0.5
-
cpe:2.3:a:ffmpeg:ffmpeg:0.5.1
-
cpe:2.3:a:ffmpeg:ffmpeg:0.5.2
-
cpe:2.3:a:ffmpeg:ffmpeg:0.5.3
-
cpe:2.3:a:mplayerhq:mplayer:1.5
-
cpe:2.3:a:mplayerhq:mplayer:svn-r38374-13.0.1