CVE-2009-4632Ffmpeg vulnerability

CWE-1895 documents5 sources
Severity
5.8MEDIUMNVD
EPSS
3.5%
top 12.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 10
Latest updateMay 2

Description

oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers to obtain sensitive memory contents and cause a denial of service via a crafted file that triggers an out-of-bounds read.

CVSS vector

AV:N/AC:M/C:P/I:N/A:PExploitability: 8.6 | Impact: 4.9

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 4:0.5+svn20090706-3 (bookworm)
Debianffmpeg/ffmpeg< 4:0.5+svn20090706-3+3
NVDffmpeg/ffmpeg0.5

🔴Vulnerability Details

2
GHSA
GHSA-p7gc-v34v-9vc8: oggparsevorbis2022-05-02
OSV
CVE-2009-4632: oggparsevorbis2010-02-10

📋Vendor Advisories

2
Ubuntu
FFmpeg vulnerabilities2010-04-19
Debian
CVE-2009-4632: ffmpeg - oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithme...2009