CVE-2008-4867
published 2008-11-01CVE-2008-4867: Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.38%
82.0th percentile
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 0.svn20080206-14 (bookworm) | ffmpeg 0.svn20080206-14 (bookworm) |
| debian | mplayer | < ffmpeg 0.svn20080206-14 (bookworm) | ffmpeg 0.svn20080206-14 (bookworm) |
| ffmpeg | ffmpeg | <= 0.4.9 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-14 | 0.svn20080206-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2vw-xfxf-2fwh: Buffer overflow in libavcodec/dca
ghsa_unreviewed·2022-05-17
CVE-2008-4867 [HIGH] CWE-119 GHSA-x2vw-xfxf-2fwh: Buffer overflow in libavcodec/dca
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
OSV
CVE-2008-4867: Buffer overflow in libavcodec/dca
osv·2008-11-01·CVSS 10.0
CVE-2008-4867 [CRITICAL] CVE-2008-4867: Buffer overflow in libavcodec/dca
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2009-03-16·CVSS 5.0
CVE-2008-4610 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg vulnerabilities
It was discovered that FFmpeg did not correctly handle certain malformed
Ogg Media (OGM) files. If a user were tricked into opening a crafted Ogg
Media file, an attacker could cause the application using FFmpeg to crash,
leading to a denial of service. (CVE-2008-4610)
It was discovered that FFmpeg did not correctly handle certain parameters
when creating DTS streams. If a user were tricked into processing certain
commands, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. This issue only affected Ubuntu 8.10. (CVE-2008-4866)
It was discovered that FFmpeg did not correctly handle certain malformed
DTS Coherent Acoustics (
Debian
CVE-2008-4867: ffmpeg - Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MP...
vendor_debian·2008·CVSS 10.0
CVE-2008-4867 [CRITICAL] CVE-2008-4867: ffmpeg - Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MP...
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
Scope: local
bookworm: resolved (fixed in 0.svn20080206-14)
bullseye: resolved (fixed in 0.svn20080206-14)
forky: resolved (fixed in 0.svn20080206-14)
sid: resolved (fixed in 0.svn20080206-14)
trixie: resolved (fixed in 0.svn20080206-14)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016352.htmlhttp://secunia.com/advisories/34296http://secunia.com/advisories/34385http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:013http://www.mandriva.com/security/advisories?name=MDVSA-2009:014http://www.mandriva.com/security/advisories?name=MDVSA-2009:015http://www.openwall.com/lists/oss-security/2008/10/29/6http://www.securityfocus.com/bid/33308http://www.ubuntu.com/usn/USN-734-1https://exchange.xforce.ibmcloud.com/vulnerabilities/46324http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016352.htmlhttp://secunia.com/advisories/34296http://secunia.com/advisories/34385http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:013http://www.mandriva.com/security/advisories?name=MDVSA-2009:014http://www.mandriva.com/security/advisories?name=MDVSA-2009:015http://www.openwall.com/lists/oss-security/2008/10/29/6http://www.securityfocus.com/bid/33308http://www.ubuntu.com/usn/USN-734-1https://exchange.xforce.ibmcloud.com/vulnerabilities/46324
2008-11-01
Published