CVE-2016-3062: Debian Linux

High severity, CVSS 8.8. EPSS: 4.4% chance of exploitation in the next 30 days.

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

Affected products

  • Debian Debian Linux: up to and including 8.0
  • Ffmpeg Ffmpeg: up to and including 0.10.15
  • Libav Libav: up to and including 11.6
  • Opensuse Leap: version 42.1 only

Published 2016-06-16. Last modified 2026-06-17.