CVE-2016-3062: Debian Linux
High severity, CVSS 8.8. EPSS: 4.4% chance of exploitation in the next 30 days.
The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.
Affected products
- Debian Debian Linux: up to and including 8.0
- Ffmpeg Ffmpeg: up to and including 0.10.15
- Libav Libav: up to and including 11.6
- Opensuse Leap: version 42.1 only
Published 2016-06-16. Last modified 2026-06-17.