PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-5115 Libavformat Project CVE debrief

CVE-2016-5115 is a denial-of-service issue in media parsing code associated with libavformat 57.34.103 and MPlayer. According to the supplied sources, a crafted MP3 file can trigger an out-of-bounds read in avcodec_decode_audio4, leading to service disruption rather than data modification. NVD classifies the weakness as CWE-125 and rates the issue CVSS 3.0 5.5 (Medium).

Vendor
Libavformat Project
Product
Libavformat
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-03
Original CVE updated
2026-05-13
Advisory published
2017-02-03
Advisory updated
2026-05-13

Who should care

Administrators and developers responsible for MPlayer deployments, systems embedding libavformat/libavcodec, and any service that automatically processes untrusted MP3 files should care most.

Technical summary

The vulnerability is described as an out-of-bounds read in avcodec_decode_audio4, with the affected CPE matching libavformat 57.34.103. The likely impact is denial of service when a crafted MP3 is parsed. NVD records the weakness as CWE-125 and assigns CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, so user interaction is required in the NVD scoring model.

Defensive priority

Medium. Prioritize if your environment opens attacker-supplied audio files or runs media parsing in a high-availability service.

Recommended defensive actions

  • Confirm whether any deployed package maps to the affected libavformat 57.34.103 CPE and update to a fixed build or vendor-backported package.
  • Review MPlayer and any libavcodec/libavformat-based workflows that accept untrusted MP3 input, and isolate or sandbox them where possible.
  • Limit automatic processing of user-supplied media files until patch status is verified.
  • Use the Openwall and MPlayer tracker references to validate whether your distribution has already backported a fix.

Evidence notes

The CVE record and NVD detail both identify the issue as CVE-2016-5115. NVD lists the vulnerable CPE as cpe:2.3:a:libavformat_project:libavformat:57.34.103:*:*:*:*:*:*:*, maps the weakness to CWE-125, and records CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. MITRE/NVD references an Openwall oss-security thread and MPlayer ticket 2298 as source material.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-5115 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-5115

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-5115 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5115

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.