cbcvebase.
CVE-2009-0385
published 2009-02-02

CVE-2009-0385: Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary…

PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.66%
93.2th percentile
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.

Affected

21 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianffmpeg< ffmpeg 0.svn20080206-16 (bookworm)ffmpeg 0.svn20080206-16 (bookworm)
debianmplayer< ffmpeg 0.svn20080206-16 (bookworm)ffmpeg 0.svn20080206-16 (bookworm)
debianvlc
fedoraprojectfedora
fedoraprojectfedora
ffmpegffmpeg< 0.6.30.6.3
ffmpegffmpeg>= 0 < 0.svn20080206-160.svn20080206-16
ffmpegffmpeg>= 0 < 0.svn20080206-160.svn20080206-16
ffmpegffmpeg>= 0 < 0.svn20080206-160.svn20080206-16
ffmpegffmpeg>= 0 < 0.svn20080206-160.svn20080206-16
mplayermplayer>= 0 < 1.0~rc2-141.0~rc2-14
mplayermplayer>= 0 < 1.0~rc2-141.0~rc2-14
mplayermplayer>= 0 < 1.0~rc2-141.0~rc2-14
mplayermplayer>= 0 < 1.0~rc2-141.0~rc2-14
xinexine-lib

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.