CVE-2006-4800
published 2006-09-14CVE-2006-4800: Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code…
PriorityP334high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.90%
91.1th percentile
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 0.cvs20060329-1 (bookworm) | ffmpeg 0.cvs20060329-1 (bookworm) |
| debian | mplayer | < ffmpeg 0.cvs20060329-1 (bookworm) | ffmpeg 0.cvs20060329-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 0.cvs20060329-1 | 0.cvs20060329-1 |
| ffmpeg | ffmpeg | >= 0 < 0.cvs20060329-1 | 0.cvs20060329-1 |
| ffmpeg | ffmpeg | >= 0 < 0.cvs20060329-1 | 0.cvs20060329-1 |
| ffmpeg | ffmpeg | >= 0 < 0.cvs20060329-1 | 0.cvs20060329-1 |
| mplayer | mplayer | >= 0 < 1.0~rc1-1 | 1.0~rc1-1 |
| mplayer | mplayer | >= 0 < 1.0~rc1-1 | 1.0~rc1-1 |
| mplayer | mplayer | >= 0 < 1.0~rc1-1 | 1.0~rc1-1 |
| mplayer | mplayer | >= 0 < 1.0~rc1-1 | 1.0~rc1-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4qm4-cvh9-rfwh: Multiple buffer overflows in libavcodec in ffmpeg before 0
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2006-4800 [HIGH] GHSA-4qm4-cvh9-rfwh: Multiple buffer overflows in libavcodec in ffmpeg before 0
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
OSV
CVE-2006-4800: Multiple buffer overflows in libavcodec in ffmpeg before 0
osv·2006-09-14·CVSS 7.5
CVE-2006-4800 [HIGH] CVE-2006-4800: Multiple buffer overflows in libavcodec in ffmpeg before 0
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
Ubuntu
ffmpeg, xine-lib vulnerabilities
vendor_ubuntu·2006-10-05·CVSS 7.5
CVE-2006-4800 [HIGH] ffmpeg, xine-lib vulnerabilities
Title: ffmpeg, xine-lib vulnerabilities
Summary: ffmpeg, xine-lib vulnerabilities
XFOCUS Security Team discovered that the AVI decoder used in xine-lib did not
correctly validate certain headers. By tricking a user into playing an AVI
with malicious headers, an attacker could execute arbitrary code with the
target user's privileges. (CVE-2006-4799)
Multiple integer overflows were discovered in ffmpeg and tools that contain a
copy of ffmpeg (like xine-lib and kino), for several types of video formats.
By tricking a user into running a video player that uses ffmpeg on a stream
with malicious content, an attacker could execute arbitrary code with the
target user's privileges. (CVE-2006-4800)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-4800: ffmpeg - Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow r...
vendor_debian·2006·CVSS 7.5
CVE-2006-4800 [HIGH] CVE-2006-4800: ffmpeg - Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow r...
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
Scope: local
bookworm: resolved (fixed in 0.cvs20060329-1)
bullseye: resolved (fixed in 0.cvs20060329-1)
forky: resolved (fixed in 0.cvs20060329-1)
sid: resolved (fixed in 0.cvs20060329-1)
trixie: resolved (fixed in 0.cvs20060329-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=133520http://secunia.com/advisories/21921http://secunia.com/advisories/22180http://secunia.com/advisories/22181http://secunia.com/advisories/22182http://secunia.com/advisories/22198http://secunia.com/advisories/22200http://secunia.com/advisories/22201http://secunia.com/advisories/22202http://secunia.com/advisories/22203http://secunia.com/advisories/22230http://secunia.com/advisories/23010http://secunia.com/advisories/23213http://security.gentoo.org/glsa/glsa-200609-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:173http://www.mandriva.com/security/advisories?name=MDKSA-2006:174http://www.mandriva.com/security/advisories?name=MDKSA-2006:175http://www.mandriva.com/security/advisories?name=MDKSA-2006:176http://www.novell.com/linux/security/advisories/2006_73_mono.htmlhttp://www.securityfocus.com/bid/20009http://www.ubuntu.com/usn/usn-358-1http://www.us.debian.org/security/2006/dsa-1215http://bugs.gentoo.org/show_bug.cgi?id=133520http://secunia.com/advisories/21921http://secunia.com/advisories/22180http://secunia.com/advisories/22181http://secunia.com/advisories/22182http://secunia.com/advisories/22198http://secunia.com/advisories/22200http://secunia.com/advisories/22201http://secunia.com/advisories/22202http://secunia.com/advisories/22203http://secunia.com/advisories/22230http://secunia.com/advisories/23010http://secunia.com/advisories/23213http://security.gentoo.org/glsa/glsa-200609-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:173http://www.mandriva.com/security/advisories?name=MDKSA-2006:174http://www.mandriva.com/security/advisories?name=MDKSA-2006:175http://www.mandriva.com/security/advisories?name=MDKSA-2006:176http://www.novell.com/linux/security/advisories/2006_73_mono.htmlhttp://www.securityfocus.com/bid/20009http://www.ubuntu.com/usn/usn-358-1http://www.us.debian.org/security/2006/dsa-1215
2006-09-14
Published