CVE-2016-7499
https://notcve.org/view.php?id=CVE-2016-7499
The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file. La función sbr_make_f_master en aacsbr.c en Libav 11.7 permite a atacantes remotos provocar una denegación de servicio (error de división por cero y bloqueo de aplicación) a través de un archivo mp3 manipulado. • http://www.openwall.com/lists/oss-security/2016/09/21/9 http://www.securityfocus.com/bid/93102 https://blogs.gentoo.org/ago/2016/09/21/libav-divide-by-zero-in-sbr_make_f_master-aacsbr-c https://git.libav.org/?p=libav.git%3Ba=blobdiff%3Bf=libavcodec/aacsbr.c%3Bh=7d156e525b40b197c38db17acf16730845b91e56%3Bhp=dbfb1677813ce6c531e4362d0be7ccf9fdfdd28e%3Bhb=a50a5ff29ec5a8243499769e2bb9b5509ce9fd52%3Bhpb=f55e3ff5891daf3d538b4d9176371960200d68fa • CWE-369: Divide By Zero •
CVE-2016-7424
https://notcve.org/view.php?id=CVE-2016-7424
The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file. La función put_no_rnd_pixels8_xy2_mmx en x86/rnd_template.c en libav 11.7 y versiones anteriores permite a atacantes remotos provocar una denegación de servicio (referencia a puntero NULL y caída) a través de un archivo MP3 manipulado. • http://www.debian.org/security/2016/dsa-3685 http://www.openwall.com/lists/oss-security/2016/09/16/17 http://www.openwall.com/lists/oss-security/2016/09/17/1 http://www.openwall.com/lists/oss-security/2016/09/17/4 http://www.securityfocus.com/bid/93038 https://blogs.gentoo.org/ago/2016/09/17/libav-null-pointer-dereference-in-put_no_rnd_pixels8_xy2_mmx-rnd_template-c https://bugzilla.libav.org/show_bug.cgi?id=962 https://git.libav.org/?p=libav.git • CWE-476: NULL Pointer Dereference •