The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7424