PT-2008-1026 · FFmpeg+1 · Ffmpeg+1
Tobias Klein
·
Publicado
2008-07-14
·
Atualizado
2020-11-20
·
CVE-2009-0385
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to revision 16846
libavcodec0d (affected versions not specified)
Description
The issue is related to an integer signedness error in the fourxm read header function, which can be exploited by remote attackers using a malformed 4X movie file. This exploitation can lead to the execution of arbitrary code via a NULL pointer dereference. Additionally, multiple vulnerabilities in the libavcodec0d package may compromise the confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations
For FFmpeg versions prior to revision 16846, update to a version after revision 16846 to resolve the issue.
For libavcodec0d, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ffmpeg
Libavcodec