CVE-2008-4868
published 2008-11-01CVE-2008-4868: Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack…
PriorityP431critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.30%
81.5th percentile
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < mplayer 1.0~rc2-14 (bookworm) | mplayer 1.0~rc2-14 (bookworm) |
| debian | mplayer | < mplayer 1.0~rc2-14 (bookworm) | mplayer 1.0~rc2-14 (bookworm) |
| ffmpeg | ffmpeg | <= 0.4.9 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gr66-3j29-5vv2: Unspecified vulnerability in the avcodec_close function in libavcodec/utils
ghsa_unreviewed·2022-05-17
CVE-2008-4868 [HIGH] GHSA-gr66-3j29-5vv2: Unspecified vulnerability in the avcodec_close function in libavcodec/utils
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."
OSV
CVE-2008-4868: Unspecified vulnerability in the avcodec_close function in libavcodec/utils
osv·2008-11-01·CVSS 10.0
CVE-2008-4868 [CRITICAL] CVE-2008-4868: Unspecified vulnerability in the avcodec_close function in libavcodec/utils
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."
Debian
CVE-2008-4868: ffmpeg - Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in...
vendor_debian·2008·CVSS 10.0
CVE-2008-4868 [CRITICAL] CVE-2008-4868: ffmpeg - Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in...
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016136.htmlhttp://secunia.com/advisories/34385http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://www.openwall.com/lists/oss-security/2008/10/29/6https://exchange.xforce.ibmcloud.com/vulnerabilities/46325http://archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlhttp://lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016136.htmlhttp://secunia.com/advisories/34385http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://www.openwall.com/lists/oss-security/2008/10/29/6https://exchange.xforce.ibmcloud.com/vulnerabilities/46325
2008-11-01
Published