CVE-2008-4866
published 2008-11-01CVE-2008-4866: Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.69%
90.8th percentile
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 0.svn20080206-14 (bookworm) | ffmpeg 0.svn20080206-14 (bookworm) |
| debian | mplayer | < ffmpeg 0.svn20080206-14 (bookworm) | ffmpeg 0.svn20080206-14 (bookworm) |
| ffmpeg | ffmpeg | <= 0.4.9 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3hj6-5952-76wq: Multiple buffer overflows in libavformat/utils
ghsa_unreviewed·2022-05-17
CVE-2008-4866 [HIGH] CWE-119 GHSA-3hj6-5952-76wq: Multiple buffer overflows in libavformat/utils
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
OSV
CVE-2008-4866: Multiple buffer overflows in libavformat/utils
osv·2008-11-01·CVSS 10.0
CVE-2008-4866 [CRITICAL] CVE-2008-4866: Multiple buffer overflows in libavformat/utils
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2009-03-16·CVSS 5.0
CVE-2008-4610 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg vulnerabilities
It was discovered that FFmpeg did not correctly handle certain malformed
Ogg Media (OGM) files. If a user were tricked into opening a crafted Ogg
Media file, an attacker could cause the application using FFmpeg to crash,
leading to a denial of service. (CVE-2008-4610)
It was discovered that FFmpeg did not correctly handle certain parameters
when creating DTS streams. If a user were tricked into processing certain
commands, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. This issue only affected Ubuntu 8.10. (CVE-2008-4866)
It was discovered that FFmpeg did not correctly handle certain malformed
DTS Coherent Acoustics (
Debian
CVE-2008-4866: ffmpeg - Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, ...
vendor_debian·2008·CVSS 10.0
CVE-2008-4866 [CRITICAL] CVE-2008-4866: ffmpeg - Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, ...
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
Scope: local
bookworm: resolved (fixed in 0.svn20080206-14)
bullseye: resolved (fixed in 0.svn20080206-14)
forky: resolved (fixed in 0.svn20080206-14)
sid: resolved (fixed in 0.svn20080206-14)
trixie: resolved (fixed in 0.svn20080206-14)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016011.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016012.htmlhttp://secunia.com/advisories/34296http://secunia.com/advisories/34385http://secunia.com/advisories/34845http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://www.debian.org/security/2009/dsa-1782http://www.mandriva.com/security/advisories?name=MDVSA-2009:013http://www.mandriva.com/security/advisories?name=MDVSA-2009:015http://www.openwall.com/lists/oss-security/2008/10/29/6http://www.securityfocus.com/bid/33308http://www.ubuntu.com/usn/USN-734-1https://exchange.xforce.ibmcloud.com/vulnerabilities/46322http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016011.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016012.htmlhttp://secunia.com/advisories/34296http://secunia.com/advisories/34385http://secunia.com/advisories/34845http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://www.debian.org/security/2009/dsa-1782http://www.mandriva.com/security/advisories?name=MDVSA-2009:013http://www.mandriva.com/security/advisories?name=MDVSA-2009:015http://www.openwall.com/lists/oss-security/2008/10/29/6http://www.securityfocus.com/bid/33308http://www.ubuntu.com/usn/USN-734-1https://exchange.xforce.ibmcloud.com/vulnerabilities/46322
2008-11-01
Published