VDB
CVE-2009-0385
CVE-2009-0385
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
EPSS 11.55% · 93.8th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
11.55%
93.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 4.0, 6.0, 5.0 |
| n/a | n/a | n/a |
| canonical | ubuntu_linux | 8.10, 8.04, 7.10 |
| ffmpeg | ffmpeg | 0 |
| fedoraproject | fedora | 9, 10 |
Timeline
- Feb 2, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Nov 8, 2023 EPSS Score
References
- ADV-2009-0277 vdb
- http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&r2=16846&pathrev=16846 url
- 34845 third-party-advisory
- 33711 third-party-advisory
- 33502 vdb
- DSA-1781 vendor-advisory
- 51643 vdb
- USN-734-1 vendor-advisory
- 34905 third-party-advisory
- DSA-1782 vendor-advisory
- http://git.ffmpeg.org/?p=ffmpeg%3Ba=commitdiff%3Bh=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17 url
- FEDORA-2009-3428 vendor-advisory
- 34385 third-party-advisory
- GLSA-200903-33 vendor-advisory
- MDVSA-2009:297 vendor-advisory
- FEDORA-2009-3433 vendor-advisory
- ffmpeg-fourxmreadheader-code-execution(48330) vdb
- 34296 third-party-advisory
- 34712 third-party-advisory
- http://svn.mplayerhq.hu/ffmpeg?view=rev&revision=16846 url
…and 4 more