logo

LibAVCodec AMV Out of Array Write

ID: 2a8a0843-a910-5096-9768-2819644225dd

STIX ID: report--2a8a0843-a910-5096-9768-2819644225dd

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

ADMIRALTY:B6
...
...

This report documents a high-risk vulnerability (CVE-2011-1931) in LibAVCodec's AMV decoder that permits an out-of-array write and potential arbitrary code execution via malformed AMV files; it was demonstrated against VLC media player 1.1.9 and earlier, and the advisory includes crash diagnostics, a patch diff, and a link to the fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.