CVE-2010-3429
published 2010-09-30CVE-2010-3429: flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted…
PriorityP340medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.18%
89.9th percentile
flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 4:0.5.2-6 (bookworm) | ffmpeg 4:0.5.2-6 (bookworm) |
| ffmpeg | ffmpeg | <= 0.6 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 4:0.5.2-6 | 4:0.5.2-6 |
| ffmpeg | ffmpeg | >= 0 < 4:0.5.2-6 | 4:0.5.2-6 |
| ffmpeg | ffmpeg | >= 0 < 4:0.5.2-6 | 4:0.5.2-6 |
| ffmpeg | ffmpeg | >= 0 < 4:0.5.2-6 | 4:0.5.2-6 |
| mplayerhq | mplayer | <= 1.0 | — |
| mplayerhq | mplayer | — | — |
| mplayerhq | mplayer | — | — |
| mplayerhq | mplayer | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v73j-5247-67hg: flicvideo
ghsa_unreviewed·2022-05-14
CVE-2010-3429 [MEDIUM] CWE-94 GHSA-v73j-5247-67hg: flicvideo
flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."
OSV
CVE-2010-3429: flicvideo
osv·2010-09-30·CVSS 6.8
CVE-2010-3429 [MEDIUM] CVE-2010-3429: flicvideo
flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2011-04-04·CVSS 6.8
CVE-2010-4704 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to run programs as your login if it opened a specially
crafted file.
Cesar Bernardini and Felipe Andres Manzano discovered that FFmpeg
incorrectly handled certain malformed flic files. If a user were tricked
into opening a crafted flic file, an attacker could cause a denial of
service via application crash, or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3429)
Dan Rosenberg discovered that FFmpeg incorrectly handled certain malformed
wmv files. If a user were tricked into opening a crafted wmv file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileg
Debian
CVE-2010-3429: ffmpeg - flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and othe...
vendor_debian·2010·CVSS 6.8
CVE-2010-3429 [MEDIUM] CVE-2010-3429: ffmpeg - flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and othe...
flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."
Scope: local
bookworm: resolved (fixed in 4:0.5.2-6)
bullseye: resolved (fixed in 4:0.5.2-6)
forky: resolved (fixed in 4:0.5.2-6)
sid: resolved (fixed in 4:0.5.2-6)
trixie: resolved (fixed in 4:0.5.2-6)
No detection rules found.
Bugzilla
CVE-2010-3429 ffmpeg: arbitrary offset dereference vulnerability in flic video codec (oCERT-2010-004) [fedora-12]
bugzilla·2010-09-28·CVSS 6.8
CVE-2010-3429 [MEDIUM] CVE-2010-3429 ffmpeg: arbitrary offset dereference vulnerability in flic video codec (oCERT-2010-004) [fedora-12]
CVE-2010-3429 ffmpeg: arbitrary offset dereference vulnerability in flic video codec (oCERT-2010-004) [fedora-12]
fedora-12 tracking bug for libextractor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Enrico noted this:
ffmpeg support in libextractor is disabled because 'mpeg2dec' requirement is
not available in fedora:
| checking whether to enable the FFmpeg thumbnail extractor... no
Closing this as NOTABUG.
Bugzilla
CVE-2010-3429 ffmpeg: arbitrary offset dereference vulnerability in flic video codec (oCERT-2010-004)
bugzilla·2010-09-20·CVSS 6.8
CVE-2010-3429 [MEDIUM] CVE-2010-3429 ffmpeg: arbitrary offset dereference vulnerability in flic video codec (oCERT-2010-004)
CVE-2010-3429 ffmpeg: arbitrary offset dereference vulnerability in flic video codec (oCERT-2010-004)
oCERT reported a vulnerability that affects the flic video codec support in ffmpeg. Quoting:
"The MPlayer package [1] is vulnerable to an arbitrary offset dereference
vulnerability, which could be exploited by malicious remote attacker. The
vulnerability is caused by the MPlayer's flic codec (flicvideo.c) on 8 bits
per pixel videos because the codec does not check received values. This could
be exploited jumping to arbitrary code by opening a specially crafted file."
They were particularly concerned about the ffmpeg inclusion in mplayer. The affected file (flicvideo.c) is also present in libextractor as provided by Fedora 12. It looks as though the only thing using libextractor in Fedor
http://git.ffmpeg.org/?p=ffmpeg%3Ba=commit%3Bh=16c592155f117ccd7b86006c45aacc692a81c23bhttp://secunia.com/advisories/41626http://secunia.com/advisories/43323http://www.debian.org/security/2011/dsa-2165http://www.mandriva.com/security/advisories?name=MDVSA-2011:060http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:062http://www.mandriva.com/security/advisories?name=MDVSA-2011:088http://www.mandriva.com/security/advisories?name=MDVSA-2011:089http://www.mandriva.com/security/advisories?name=MDVSA-2011:112http://www.mandriva.com/security/advisories?name=MDVSA-2011:114http://www.ocert.org/advisories/ocert-2010-004.htmlhttp://www.openwall.com/lists/oss-security/2010/09/28/4http://www.securityfocus.com/archive/1/514009/100/0/threadedhttp://www.ubuntu.com/usn/usn-1104-1/http://www.vupen.com/english/advisories/2010/2517http://www.vupen.com/english/advisories/2010/2518http://www.vupen.com/english/advisories/2011/1241https://bugzilla.redhat.com/show_bug.cgi?id=635775http://git.ffmpeg.org/?p=ffmpeg%3Ba=commit%3Bh=16c592155f117ccd7b86006c45aacc692a81c23bhttp://secunia.com/advisories/41626http://secunia.com/advisories/43323http://www.debian.org/security/2011/dsa-2165http://www.mandriva.com/security/advisories?name=MDVSA-2011:060http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:062http://www.mandriva.com/security/advisories?name=MDVSA-2011:088http://www.mandriva.com/security/advisories?name=MDVSA-2011:089http://www.mandriva.com/security/advisories?name=MDVSA-2011:112http://www.mandriva.com/security/advisories?name=MDVSA-2011:114http://www.ocert.org/advisories/ocert-2010-004.htmlhttp://www.openwall.com/lists/oss-security/2010/09/28/4http://www.securityfocus.com/archive/1/514009/100/0/threadedhttp://www.ubuntu.com/usn/usn-1104-1/http://www.vupen.com/english/advisories/2010/2517http://www.vupen.com/english/advisories/2010/2518http://www.vupen.com/english/advisories/2011/1241https://bugzilla.redhat.com/show_bug.cgi?id=635775
2010-09-30
Published