CVE-2016-3062 is a memory corruption vulnerability in the mov_read_dref function of Libav and FFmpeg, affecting versions before 11.7 and 0.11 respectively, and present in products like Debian and OpenSUSE. This high-severity flaw (CVSS 8.8) can be triggered remotely by an unauthenticated attacker through a crafted MP4 file, potentially leading to denial of service or arbitrary code execution. Despite its age, a recent SecurityWeek article highlights that similar long-patched vulnerabilities still exist in popular Android apps. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not on the CISA KEV catalog, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.6CPE matchmatch criteria | cpe:2.3:a:libav:libav:*:*:*:*:*:*:*:* | ||
<= 0.10.15CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | ||
<= 8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.