PT-2008-1026 · FFmpeg+1 · Ffmpeg+1

Tobias Klein

·

Publicado

2008-07-14

·

Atualizado

2020-11-20

·

CVE-2009-0385

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to revision 16846 libavcodec0d (affected versions not specified)
Description The issue is related to an integer signedness error in the fourxm read header function, which can be exploited by remote attackers using a malformed 4X movie file. This exploitation can lead to the execution of arbitrary code via a NULL pointer dereference. Additionally, multiple vulnerabilities in the libavcodec0d package may compromise the confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations For FFmpeg versions prior to revision 16846, update to a version after revision 16846 to resolve the issue. For libavcodec0d, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02204
CVE-2009-0385
DSA-1781-1
DSA-1782-1

Produtos afetados

Ffmpeg
Libavcodec