CVE-2006-4800Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
6.3%
top 9.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 1

Description

Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

debiandebian/ffmpeg< ffmpeg 0.cvs20060329-1 (bookworm)
Debianffmpeg/ffmpeg< 0.cvs20060329-1+3
NVDffmpeg/ffmpeg4 versions+3
debiandebian/mplayer< ffmpeg 0.cvs20060329-1 (bookworm)
Debianmplayer/mplayer< 1.0~rc1-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4qm4-cvh9-rfwh: Multiple buffer overflows in libavcodec in ffmpeg before 02022-05-01
OSV
CVE-2006-4800: Multiple buffer overflows in libavcodec in ffmpeg before 02006-09-14

📋Vendor Advisories

2
Ubuntu
ffmpeg, xine-lib vulnerabilities2006-10-05
Debian
CVE-2006-4800: ffmpeg - Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow r...2006