CVE-2009-0385
published 2009-02-02CVE-2009-0385: Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.66%
93.2th percentile
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 0.svn20080206-16 (bookworm) | ffmpeg 0.svn20080206-16 (bookworm) |
| debian | mplayer | < ffmpeg 0.svn20080206-16 (bookworm) | ffmpeg 0.svn20080206-16 (bookworm) |
| debian | vlc | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ffmpeg | ffmpeg | < 0.6.3 | 0.6.3 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-16 | 0.svn20080206-16 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-16 | 0.svn20080206-16 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-16 | 0.svn20080206-16 |
| ffmpeg | ffmpeg | >= 0 < 0.svn20080206-16 | 0.svn20080206-16 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| mplayer | mplayer | >= 0 < 1.0~rc2-14 | 1.0~rc2-14 |
| xine | xine-lib | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jhxf-rmj6-ghq6: Integer overflow in the 4xm demuxer (demuxers/demux_4xm
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-0698 [CRITICAL] GHSA-jhxf-rmj6-ghq6: Integer overflow in the 4xm demuxer (demuxers/demux_4xm
Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.
GHSA
GHSA-h3wc-jxm7-mr49: Integer signedness error in the fourxm_read_header function in libavformat/4xm
ghsa_unreviewed·2022-05-02
CVE-2009-0385 [HIGH] GHSA-h3wc-jxm7-mr49: Integer signedness error in the fourxm_read_header function in libavformat/4xm
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
OSV
CVE-2009-0385: Integer signedness error in the fourxm_read_header function in libavformat/4xm
osv·2009-02-02·CVSS 9.3
CVE-2009-0385 [CRITICAL] CVE-2009-0385: Integer signedness error in the fourxm_read_header function in libavformat/4xm
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2009-03-16·CVSS 5.0
CVE-2008-4610 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg vulnerabilities
It was discovered that FFmpeg did not correctly handle certain malformed
Ogg Media (OGM) files. If a user were tricked into opening a crafted Ogg
Media file, an attacker could cause the application using FFmpeg to crash,
leading to a denial of service. (CVE-2008-4610)
It was discovered that FFmpeg did not correctly handle certain parameters
when creating DTS streams. If a user were tricked into processing certain
commands, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. This issue only affected Ubuntu 8.10. (CVE-2008-4866)
It was discovered that FFmpeg did not correctly handle certain malformed
DTS Coherent Acoustics (
Debian
CVE-2009-0385: ffmpeg - Integer signedness error in the fourxm_read_header function in libavformat/4xm.c...
vendor_debian·2009·CVSS 9.3
CVE-2009-0385 [CRITICAL] CVE-2009-0385: ffmpeg - Integer signedness error in the fourxm_read_header function in libavformat/4xm.c...
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.svn20080206-16)
bullseye: resolved (fixed in 0.svn20080206-16)
forky: resolved (fixed in 0.svn20080206-16)
sid: resolved (fixed in 0.svn20080206-16)
trixie: resolved (fixed in 0.svn20080206-16)
Debian
CVE-2009-0698: vlc - Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 ...
vendor_debian·2009·CVSS 9.3
CVE-2009-0698 [CRITICAL] CVE-2009-0698: vlc - Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 ...
Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.ffmpeg.org/?p=ffmpeg%3Ba=commitdiff%3Bh=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17http://osvdb.org/51643http://secunia.com/advisories/33711http://secunia.com/advisories/34296http://secunia.com/advisories/34385http://secunia.com/advisories/34712http://secunia.com/advisories/34845http://secunia.com/advisories/34905http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&r2=16846&pathrev=16846http://svn.mplayerhq.hu/ffmpeg?view=rev&revision=16846http://www.debian.org/security/2009/dsa-1781http://www.debian.org/security/2009/dsa-1782http://www.mandriva.com/security/advisories?name=MDVSA-2009:297http://www.securityfocus.com/archive/1/500514/100/0/threadedhttp://www.securityfocus.com/bid/33502http://www.trapkit.de/advisories/TKADV2009-004.txthttp://www.ubuntu.com/usn/USN-734-1http://www.vupen.com/english/advisories/2009/0277https://exchange.xforce.ibmcloud.com/vulnerabilities/48330https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00210.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00215.htmlhttp://git.ffmpeg.org/?p=ffmpeg%3Ba=commitdiff%3Bh=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17http://osvdb.org/51643http://secunia.com/advisories/33711http://secunia.com/advisories/34296http://secunia.com/advisories/34385http://secunia.com/advisories/34712http://secunia.com/advisories/34845http://secunia.com/advisories/34905http://security.gentoo.org/glsa/glsa-200903-33.xmlhttp://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&r2=16846&pathrev=16846http://svn.mplayerhq.hu/ffmpeg?view=rev&revision=16846http://www.debian.org/security/2009/dsa-1781http://www.debian.org/security/2009/dsa-1782http://www.mandriva.com/security/advisories?name=MDVSA-2009:297http://www.securityfocus.com/archive/1/500514/100/0/threadedhttp://www.securityfocus.com/bid/33502http://www.trapkit.de/advisories/TKADV2009-004.txthttp://www.ubuntu.com/usn/USN-734-1http://www.vupen.com/english/advisories/2009/0277https://exchange.xforce.ibmcloud.com/vulnerabilities/48330https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00210.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00215.html
2009-02-02
Published