PT-2008-1026 · FFmpeg+1 · Ffmpeg+1

Tobias Klein

·

Published

2008-07-14

·

Updated

2020-11-20

·

CVE-2009-0385

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to revision 16846 libavcodec0d (affected versions not specified)
Description The issue is related to an integer signedness error in the fourxm read header function, which can be exploited by remote attackers using a malformed 4X movie file. This exploitation can lead to the execution of arbitrary code via a NULL pointer dereference. Additionally, multiple vulnerabilities in the libavcodec0d package may compromise the confidentiality, integrity, and availability of protected information, with potential for remote exploitation.
Recommendations For FFmpeg versions prior to revision 16846, update to a version after revision 16846 to resolve the issue. For libavcodec0d, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02204
CVE-2009-0385
DSA-1781-1
DSA-1782-1

Affected Products

Ffmpeg
Libavcodec