CVE-2009-4639
published 2010-02-10CVE-2009-4639: The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.00%
86.0th percentile
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2010-04-19
CVE-2009-4632 FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg vulnerabilities
It was discovered that FFmpeg contained multiple security issues when
handling certain multimedia files. If a user were tricked into opening a
crafted multimedia file, an attacker could cause a denial of service via
application crash, or possibly execute arbitrary code with the privileges
of the user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-4639: ffmpeg - The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attac...
vendor_debian·2009·CVSS 4.3
CVE-2009-4639 [MEDIUM] CVE-2009-4639: ffmpeg - The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attac...
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-4x29-4984-2qcp: The av_rescale_rnd function in the AVI demuxer in FFmpeg 0
ghsa_unreviewed·2022-05-02
CVE-2009-4639 [MEDIUM] GHSA-4x29-4984-2qcp: The av_rescale_rnd function in the AVI demuxer in FFmpeg 0
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.
OSV
CVE-2009-4639: The av_rescale_rnd function in the AVI demuxer in FFmpeg 0
osv·2010-02-10·CVSS 4.3
CVE-2009-4639 [MEDIUM] CVE-2009-4639: The av_rescale_rnd function in the AVI demuxer in FFmpeg 0
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://scarybeastsecurity.blogspot.com/2009/09/patching-ffmpeg-into-shape.htmlhttp://secunia.com/advisories/36805http://secunia.com/advisories/39482http://www.mandriva.com/security/advisories?name=MDVSA-2011:059http://www.mandriva.com/security/advisories?name=MDVSA-2011:060http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:088http://www.mandriva.com/security/advisories?name=MDVSA-2011:112http://www.securityfocus.com/bid/36465http://www.ubuntu.com/usn/USN-931-1http://www.vupen.com/english/advisories/2010/0935http://www.vupen.com/english/advisories/2011/1241https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240https://roundup.ffmpeg.org/roundup/ffmpeg/issue1245http://scarybeastsecurity.blogspot.com/2009/09/patching-ffmpeg-into-shape.htmlhttp://secunia.com/advisories/36805http://secunia.com/advisories/39482http://www.mandriva.com/security/advisories?name=MDVSA-2011:059http://www.mandriva.com/security/advisories?name=MDVSA-2011:060http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:088http://www.mandriva.com/security/advisories?name=MDVSA-2011:112http://www.securityfocus.com/bid/36465http://www.ubuntu.com/usn/USN-931-1http://www.vupen.com/english/advisories/2010/0935http://www.vupen.com/english/advisories/2011/1241https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240https://roundup.ffmpeg.org/roundup/ffmpeg/issue1245
2010-02-10
Published