VDB
CVE-2008-3162
CVE-2008-3162
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.
EPSS 26.47% · 96.4th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
26.47%
96.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ffmpeg | ffmpeg | 0.4.9, 0.3, 0.3.1 |
| n/a | n/a | n/a |
Timeline
- Jul 9, 2008 PoC Published
- Jul 14, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 30154 vdb
- USN-630-1 vendor-advisory
- DSA-1781 vendor-advisory
- [oss-security] 20080710 CVE id request: libavformat mailing-list
- 31268 third-party-advisory
- 30994 third-party-advisory
- ADV-2008-2031 vdb
- 34905 third-party-advisory
- [oss-security] 20080716 Re: CVE id request: libavformat mailing-list
- https://roundup.mplayerhq.hu/roundup/ffmpeg/issue311 url
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=489965 url
- 34385 third-party-advisory
- GLSA-200903-33 vendor-advisory
- MDVSA-2008:157 vendor-advisory
- http://svn.mplayerhq.hu/ffmpeg?view=rev&revision=13993 url
- https://nvd.nist.gov/vuln/detail/CVE-2008-3162 advisory