PT-2008-1026 · FFmpeg+1 · Ffmpeg+1
Tobias Klein
·
Published
2008-07-14
·
Updated
2020-11-20
·
CVE-2009-0385
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to revision 16846
libavcodec0d (affected versions not specified)
Description
The issue is related to an integer signedness error in the fourxm read header function, which can be exploited by remote attackers using a malformed 4X movie file. This exploitation can lead to the execution of arbitrary code via a NULL pointer dereference. Additionally, multiple vulnerabilities in the libavcodec0d package may compromise the confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations
For FFmpeg versions prior to revision 16846, update to a version after revision 16846 to resolve the issue.
For libavcodec0d, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Libavcodec