CVE-2005-4048Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
7.5HIGHNVD
EPSS
5.2%
top 10.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateMay 1

Description

Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Debianffmpeg/ffmpeg< 0.cvs20050918-5.1+3
NVDffmpeg/ffmpeg5 versions+4
Debianvideolan/vlc_media_player< 0.8.4.debian-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f7pg-m34f-mphj: Heap-based buffer overflow in the avcodec_default_get_buffer function (utils2022-05-01
CVEList
CVE-2005-4048: Heap-based buffer overflow in the avcodec_default_get_buffer function (utils2005-12-07
OSV
CVE-2005-4048: Heap-based buffer overflow in the avcodec_default_get_buffer function (utils2005-12-07

📋Vendor Advisories

3
Ubuntu
ffmpeg/xine-lib vulnerability2005-12-16
Ubuntu
ffmpeg vulnerability2005-12-15
Debian
CVE-2005-4048: ffmpeg - Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) ...2005
CVE-2005-4048 — Ffmpeg vulnerability | cvebase