{"id":"CVE-2016-8675","details":"The get_vlc2 function in get_bits.h in Libav before 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file, possibly related to startcode sequences during m4v detection.","modified":"2026-07-08T15:09:44.268112Z","published":"2017-02-15T21:59:00.357Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/93468"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/10/16/13"},{"type":"FIX","url":"https://blogs.gentoo.org/ago/2016/09/07/libav-null-pointer-dereference-in-get_vlc2_get_bits_h/"},{"type":"FIX","url":"https://github.com/libav/libav/commit/e5b019725f53b79159931d3a7317107cbbfd0860"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libav/libav","events":[{"introduced":"0"},{"last_affected":"3c3a0a06804e901cb9d6d94784a4ec8ecb8fe9e2"},{"fixed":"e5b019725f53b79159931d3a7317107cbbfd0860"}],"database_specific":{"cpe":"cpe:2.3:a:libav:libav:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"11.8"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v11.8","v11.7","v11.6","v11.5","v11.4","v11.3","v11.2","v11.1","v11","v12_dev0","v11_beta1","v11_alpha2","v11_alpha1","v10_beta1","v11_dev0","dev14.2","v10_alpha2","v10_alpha1","v9","v9_beta3","v9_beta2","v9_beta1","v0.8","v0.8b2","v0.8b1","v0.7","v0.7rc1","v0.7b2","v0.7b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8675.json","vanir_signatures_modified":"2026-07-08T15:09:44Z","vanir_signatures":[{"id":"CVE-2016-8675-3b92c3ec","signature_type":"Line","signature_version":"v1","source":"https://github.com/libav/libav/commit/e5b019725f53b79159931d3a7317107cbbfd0860","target":{"file":"libavformat/m4vdec.c"},"deprecated":false,"digest":{"line_hashes":["321142693121010581418646289099016438489","239633447114481679835775621707483041135","11291889930034608089616714022836546254","99106633299237376193173656402539085251","336722905847517177462785648080400559155","13778668871422286883308215251849905423","241465393658360743125963036776765630424","296174214188742991122586453178002203646","83486387580032572371839461737775151824","285141421795515565073026816415658987073","129088873199073268276711779281431234541","224930657538715393918074217486063946203"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"187451337293397042913815863985845387980","length":636},"id":"CVE-2016-8675-ba51d928","signature_type":"Function","signature_version":"v1","source":"https://github.com/libav/libav/commit/e5b019725f53b79159931d3a7317107cbbfd0860","target":{"file":"libavformat/m4vdec.c","function":"mpeg4video_probe"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}