PatchSiren cyber security CVE debrief
CVE-2016-5115 Libavformat Project CVE debrief
CVE-2016-5115 is a denial-of-service issue in media parsing code associated with libavformat 57.34.103 and MPlayer. According to the supplied sources, a crafted MP3 file can trigger an out-of-bounds read in avcodec_decode_audio4, leading to service disruption rather than data modification. NVD classifies the weakness as CWE-125 and rates the issue CVSS 3.0 5.5 (Medium).
- Vendor
- Libavformat Project
- Product
- Libavformat
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-05-13
Who should care
Administrators and developers responsible for MPlayer deployments, systems embedding libavformat/libavcodec, and any service that automatically processes untrusted MP3 files should care most.
Technical summary
The vulnerability is described as an out-of-bounds read in avcodec_decode_audio4, with the affected CPE matching libavformat 57.34.103. The likely impact is denial of service when a crafted MP3 is parsed. NVD records the weakness as CWE-125 and assigns CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, so user interaction is required in the NVD scoring model.
Defensive priority
Medium. Prioritize if your environment opens attacker-supplied audio files or runs media parsing in a high-availability service.
Recommended defensive actions
- Confirm whether any deployed package maps to the affected libavformat 57.34.103 CPE and update to a fixed build or vendor-backported package.
- Review MPlayer and any libavcodec/libavformat-based workflows that accept untrusted MP3 input, and isolate or sandbox them where possible.
- Limit automatic processing of user-supplied media files until patch status is verified.
- Use the Openwall and MPlayer tracker references to validate whether your distribution has already backported a fix.
Evidence notes
The CVE record and NVD detail both identify the issue as CVE-2016-5115. NVD lists the vulnerable CPE as cpe:2.3:a:libavformat_project:libavformat:57.34.103:*:*:*:*:*:*:*, maps the weakness to CWE-125, and records CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. MITRE/NVD references an Openwall oss-security thread and MPlayer ticket 2298 as source material.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-5115 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-5115
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-5115 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5115
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://trac.mplayerhq.hu/ticket/2298
[email protected] - Issue Tracking
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.