PT-2010-5647 · FFmpeg · Libavdevice-Dev+6

Will Dormann

·

Published

1970-01-01

·

Updated

2011-10-26

·

CVE-2009-4634

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions 0.5 and earlier libavdevice52 (affected versions not specified) libavcodec51 (affected versions not specified) libavdevice-dev (affected versions not specified) libavcodec-dev (affected versions not specified) ffmpeg-doc (affected versions not specified) ffmpeg-dbg (affected versions not specified)
Description The issue involves multiple vulnerabilities in the FFmpeg package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. This can be achieved through crafted files that bypass validation checks or access out-of-bounds memory, potentially leading to a denial of service or the execution of arbitrary code. The vulnerabilities can be exploited via vorbis dec.c and mov.c, related to an elst tag that appears before a tag that creates a stream.
Recommendations For FFmpeg version 0.5 and earlier, update to a version later than 0.5 to resolve the issue. For libavdevice52, libavcodec51, libavdevice-dev, libavcodec-dev, ffmpeg-doc, and ffmpeg-dbg, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02202
BDU:2015-02203
BDU:2015-02205
BDU:2015-02206
BDU:2015-02207
BDU:2015-02208
CVE-2009-4634
DSA-2000-1

Affected Products

Ffmpeg
Ffmpeg-Dbg
Ffmpeg-Doc
Libavcodec-Dev
Libavcodec51
Libavdevice-Dev
Libavdevice52