PatchSiren cyber security CVE debrief
CVE-2016-4352 Libavformat Project CVE debrief
CVE-2016-4352 is a denial-of-service flaw in GIF demuxing. The supplied description says large GIF dimensions can trigger an integer overflow in libmpdemux/demux_gif.c and crash MPlayer, while NVD maps the issue to libavformat_project:libavformat and rates it as a high-availability impact bug. In practice, anyone shipping affected media parsing code should treat this as a malformed-image input bug that can terminate the process when a crafted GIF is opened.
- Vendor
- Libavformat Project
- Product
- Libavformat
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-05-13
Who should care
Teams that ship or operate media players, transcoding tools, desktop apps, or libraries that parse GIF files from untrusted sources. Package maintainers and downstream distributors using affected MPlayer/libavformat code should also care, because the flaw can be triggered during ordinary file handling rather than privileged actions.
Technical summary
The issue is an integer overflow (CWE-190) in GIF demuxing. Per NVD, the CVSS 3.0 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating a local/file-opening scenario that requires user interaction and can result in process crash or denial of service. The source corpus is slightly inconsistent on component naming: the CVE description points to MPlayer's libmpdemux/demux_gif.c, while the NVD CPE marks libavformat_project:libavformat affected up to version 57.34.103.
Defensive priority
Medium
Recommended defensive actions
- Update to a vendor-fixed release or downstream package that is known to include the GIF demux overflow fix; NVD marks libavformat versions up to 57.34.103 as affected.
- Verify whether your products bundle MPlayer or libavformat GIF parsing code and inventory any deployments that open untrusted GIF files.
- Reduce exposure by limiting automatic parsing of externally supplied media and by isolating media-processing workloads where feasible.
- Treat malformed image files as untrusted input in testing and regression coverage, including oversized GIF dimensions and boundary cases.
- Monitor distro or vendor advisories tied to the Openwall oss-security report and MPlayer issue 2295 for fix guidance.
Evidence notes
The debrief is grounded in the supplied NVD record and linked references. The CVE description states that large dimensions in a GIF can cause an integer overflow in MPlayer's libmpdemux/demux_gif.c, and NVD assigns CWE-190. NVD's CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, and its CPE criteria mark libavformat_project:libavformat versions through 57.34.103 as vulnerable. The corpus also contains an Openwall oss-security post and an MPlayer issue tracker entry, which support the advisory context. The source data is inconsistent on product naming, so that discrepancy is called out rather than resolved beyond the supplied evidence.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-4352 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-4352
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-4352 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4352
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://trac.mplayerhq.hu/ticket/2295
[email protected] - Issue Tracking
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.