VDB

CVE-2009-0385

CVE-2009-0385 PUBLISHED CVSS 9.300000190734863 CRITICAL

Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.

EPSS 11.55% · 93.8th percentile

Risk Scores

CVSS 2.0
9.300000190734863
EPSS Score
11.55%
93.8th percentile

Affected Products

VendorProductVersions
debiandebian_linux4.0, 6.0, 5.0
n/an/an/a
canonicalubuntu_linux8.10, 8.04, 7.10
ffmpegffmpeg0
fedoraprojectfedora9, 10

Timeline

  • Feb 2, 2009 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
  • Nov 8, 2023 EPSS Score

References

…and 4 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›