CVE-2005-4048 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg
Severity
7.5HIGHNVD
EPSS
5.2%
top 10.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 7
Latest updateMay 1
Description
Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-f7pg-m34f-mphj: Heap-based buffer overflow in the avcodec_default_get_buffer function (utils↗2022-05-01
CVEList▶
CVE-2005-4048: Heap-based buffer overflow in the avcodec_default_get_buffer function (utils↗2005-12-07
OSV▶
CVE-2005-4048: Heap-based buffer overflow in the avcodec_default_get_buffer function (utils↗2005-12-07