PT-2010-5646 · FFmpeg · Ffmpeg

Will Dormann

·

Publicado

1970-01-01

·

Atualizado

2011-10-26

·

CVE-2009-4633

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 0.5
Description The issue is related to multiple vulnerabilities in the FFmpeg package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, in vorbis dec.c, an assignment operator is used instead of a comparison operator, potentially allowing remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted file that modifies a loop counter and triggers a heap-based buffer overflow.
Recommendations For FFmpeg version prior to 0.5, update to a version that fixes the vulnerabilities, as the current version may allow remote attackers to exploit the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02202
BDU:2015-02203
BDU:2015-02205
BDU:2015-02206
BDU:2015-02207
BDU:2015-02208
CVE-2009-4633
DSA-2000-1

Produtos afetados

Ffmpeg