|The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.
|CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
This was originally reported for VLC; but upstream states that it is in libavcodec
This seems to be Windows-specific issue, the reported error couldn't be reproduced
with any ffmpeg release and libav/0.8.