PT-2010-5647 · FFmpeg · Libavdevice-Dev+6
Will Dormann
·
Published
1970-01-01
·
Updated
2011-10-26
·
CVE-2009-4634
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions 0.5 and earlier
libavdevice52 (affected versions not specified)
libavcodec51 (affected versions not specified)
libavdevice-dev (affected versions not specified)
libavcodec-dev (affected versions not specified)
ffmpeg-doc (affected versions not specified)
ffmpeg-dbg (affected versions not specified)
Description
The issue involves multiple vulnerabilities in the FFmpeg package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. This can be achieved through crafted files that bypass validation checks or access out-of-bounds memory, potentially leading to a denial of service or the execution of arbitrary code. The vulnerabilities can be exploited via
vorbis dec.c and mov.c, related to an elst tag that appears before a tag that creates a stream.Recommendations
For FFmpeg version 0.5 and earlier, update to a version later than 0.5 to resolve the issue.
For libavdevice52, libavcodec51, libavdevice-dev, libavcodec-dev, ffmpeg-doc, and ffmpeg-dbg, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Ffmpeg-Dbg
Ffmpeg-Doc
Libavcodec-Dev
Libavcodec51
Libavdevice-Dev
Libavdevice52