CVE-2010-4705Ffmpeg vulnerability

CWE-1893 documents3 sources
Severity
9.3CRITICALNVD
EPSS
0.5%
top 34.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 22
Latest updateMay 17

Description

Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg, possibly 0.6, has unspecified impact and remote attack vectors, related to the sizes of certain integer data types. NOTE: this might overlap CVE-2011-0480.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDffmpeg/ffmpeg0.6
debiandebian/ffmpeg

🔴Vulnerability Details

1
GHSA
GHSA-qmwc-7x28-rrw2: Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vorbis_dec2022-05-17

📋Vendor Advisories

1
Debian
CVE-2010-4705: ffmpeg - Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vo...2010