Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-4637Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
10.0CRITICALNVD
EPSS
33.8%
top 3.03%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 10
Latest updateMay 2

Description

FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 4:0.5+svn20090706-3 (bookworm)
Debianffmpeg/ffmpeg< 4:0.5+svn20090706-3+3
NVDffmpeg/ffmpeg0.5

🔴Vulnerability Details

2
GHSA
GHSA-v8f9-pj55-fp23: FFmpeg 02022-05-02
OSV
CVE-2009-4637: FFmpeg 02010-02-10

💥Exploits & PoCs

1
Exploit-DB
FFmpeg 0.5 - Multiple Remote Vulnerabilities2009-09-21

📋Vendor Advisories

2
Ubuntu
FFmpeg vulnerabilities2010-04-19
Debian
CVE-2009-4637: ffmpeg - FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and poss...2009