CVE-2008-4201
published 2008-09-24CVE-2008-4201: Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.65%
93.1th percentile
Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| audiocoding | faad2 | <= 2.6.1 | — |
| audiocoding | faad2 | — | — |
| audiocoding | faad2 | — | — |
| audiocoding | faad2 | — | — |
| debian | faad2 | < faad2 2.6.1-3.1 (bookworm) | faad2 2.6.1-3.1 (bookworm) |
| faad2_project | faad2 | >= 0 < 2.6.1-3.1 | 2.6.1-3.1 |
| faad2_project | faad2 | >= 0 < 2.6.1-3.1 | 2.6.1-3.1 |
| faad2_project | faad2 | >= 0 < 2.6.1-3.1 | 2.6.1-3.1 |
| faad2_project | faad2 | >= 0 < 2.6.1-3.1 | 2.6.1-3.1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v676-q56x-42jv: Heap-based buffer overflow in the decodeMP4file function (frontend/main
ghsa_unreviewed·2022-05-02
CVE-2008-4201 [HIGH] CWE-119 GHSA-v676-q56x-42jv: Heap-based buffer overflow in the decodeMP4file function (frontend/main
Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.
OSV
CVE-2008-4201: Heap-based buffer overflow in the decodeMP4file function (frontend/main
osv·2008-09-24·CVSS 9.3
CVE-2008-4201 [CRITICAL] CVE-2008-4201: Heap-based buffer overflow in the decodeMP4file function (frontend/main
Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.
Debian
CVE-2008-4201: faad2 - Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FA...
vendor_debian·2008·CVSS 9.3
CVE-2008-4201 [CRITICAL] CVE-2008-4201: faad2 - Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FA...
Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.
Scope: local
bookworm: resolved (fixed in 2.6.1-3.1)
bullseye: resolved (fixed in 2.6.1-3.1)
forky: resolved (fixed in 2.6.1-3.1)
sid: resolved (fixed in 2.6.1-3.1)
trixie: resolved (fixed in 2.6.1-3.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499899http://bugs.gentoo.org/attachment.cgi?id=166174&action=viewhttp://bugs.gentoo.org/show_bug.cgi?id=238445http://osvdb.org/48349http://secunia.com/advisories/32006http://secunia.com/advisories/32661http://security.gentoo.org/glsa/glsa-200811-03.xmlhttp://www.audiocoding.com/archive.htmlhttp://www.audiocoding.com/patch/main_overflow.diffhttp://www.openwall.com/lists/oss-security/2008/09/24/6http://www.securityfocus.com/bid/31219http://www.vupen.com/english/advisories/2008/2601http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499899http://bugs.gentoo.org/attachment.cgi?id=166174&action=viewhttp://bugs.gentoo.org/show_bug.cgi?id=238445http://osvdb.org/48349http://secunia.com/advisories/32006http://secunia.com/advisories/32661http://security.gentoo.org/glsa/glsa-200811-03.xmlhttp://www.audiocoding.com/archive.htmlhttp://www.audiocoding.com/patch/main_overflow.diffhttp://www.openwall.com/lists/oss-security/2008/09/24/6http://www.securityfocus.com/bid/31219http://www.vupen.com/english/advisories/2008/2601
2008-09-24
Published