Medium severity5.5NVD Advisory· Published Oct 7, 2016· Updated May 6, 2026
CVE-2016-7424
CVE-2016-7424
Description
The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.debian.org/security/2016/dsa-3685nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/09/16/17nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2016/09/17/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2016/09/17/4nvdMailing ListThird Party Advisory
- blogs.gentoo.org/ago/2016/09/17/libav-null-pointer-dereference-in-put_no_rnd_pixels8_xy2_mmx-rnd_template-c/nvdThird Party Advisory
- www.securityfocus.com/bid/93038nvdBroken Link
- bugzilla.libav.org/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.