CVE-2011-0480
published 2011-01-14CVE-2011-0480: Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow…
PriorityP432critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.30%
81.4th percentile
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| debian | ffmpeg | — | — |
| ffmpeg | ffmpeg | <= 0.6.1 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2011-04-04·CVSS 6.8
CVE-2010-4704 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to run programs as your login if it opened a specially
crafted file.
Cesar Bernardini and Felipe Andres Manzano discovered that FFmpeg
incorrectly handled certain malformed flic files. If a user were tricked
into opening a crafted flic file, an attacker could cause a denial of
service via application crash, or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3429)
Dan Rosenberg discovered that FFmpeg incorrectly handled certain malformed
wmv files. If a user were tricked into opening a crafted wmv file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileg
Debian
CVE-2011-0480: ffmpeg - Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as us...
vendor_debian·2011·CVSS 9.3
CVE-2011-0480 [CRITICAL] CVE-2011-0480: ffmpeg - Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as us...
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
Debian
CVE-2010-4705: ffmpeg - Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vo...
vendor_debian·2010·CVSS 9.3
CVE-2010-4705 [CRITICAL] CVE-2010-4705: ffmpeg - Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vo...
Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg, possibly 0.6, has unspecified impact and remote attack vectors, related to the sizes of certain integer data types. NOTE: this might overlap CVE-2011-0480.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2010-4704: ffmpeg - libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows...
vendor_debian·2010·CVSS 4.3
CVE-2010-4704 [MEDIUM] CVE-2010-4704: ffmpeg - libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows...
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-qmwc-7x28-rrw2: Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vorbis_dec
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2010-4705 [CRITICAL] GHSA-qmwc-7x28-rrw2: Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vorbis_dec
Integer overflow in the vorbis_residue_decode_internal function in libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg, possibly 0.6, has unspecified impact and remote attack vectors, related to the sizes of certain integer data types. NOTE: this might overlap CVE-2011-0480.
GHSA
GHSA-fcg6-56gf-f98f: libavcodec/vorbis_dec
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2010-4704 [CRITICAL] CWE-20 GHSA-fcg6-56gf-f98f: libavcodec/vorbis_dec
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.
GHSA
GHSA-9vjw-qpx7-3vwc: Multiple buffer overflows in vorbis_dec
ghsa_unreviewed·2022-05-13
CVE-2011-0480 [HIGH] CWE-120 GHSA-9vjw-qpx7-3vwc: Multiple buffer overflows in vorbis_dec
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
OSV
CVE-2010-4704: libavcodec/vorbis_dec
osv·2011-01-22·CVSS 4.3
CVE-2010-4704 [MEDIUM] CVE-2010-4704: libavcodec/vorbis_dec
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.
OSV
CVE-2011-0480: Multiple buffer overflows in vorbis_dec
osv·2011-01-14·CVSS 9.3
CVE-2011-0480 [CRITICAL] CVE-2011-0480: Multiple buffer overflows in vorbis_dec
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
Suricata
ET WEB_CLIENT Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow
suricata·2011-01-05
CVE-2010-0480 ET WEB_CLIENT Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow
ET WEB_CLIENT Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow
Rule: alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET WEB_CLIENT Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow"; flow:established,to_client; flowbits:isset,ET.AVI.RIFF.Chunk; content:"|73 74 72 66|"; content:"|93 00 00 00|"; distance:8; within:4; reference:cve,2010-0480; reference:url,www.exploit-db.com/moaub-5-microsoft-mpeg-layer-3-audio-stack-based-overflow/; reference:url,www.exploit-db.com/exploits/14895/; reference:url,www.microsoft.com/technet/security/Bulletin/MS10-026.mspx; classtype:attempted-user; sid:2012143; rev:3; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2011_01_05, cve CVE_2010_0480, deployment
No writeups or analysis indexed.
http://article.gmane.org/gmane.comp.video.ffmpeg.devel/122703http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610550http://code.google.com/p/chromium/issues/detail?id=68115http://codereview.chromium.org/5964011http://codereview.chromium.org/6069005http://ffmpeg.mplayerhq.hu/http://git.ffmpeg.org/?p=ffmpeg.git%3Ba=commit%3Bh=13184036a6b1b1d4b61c91118c0896e9ad4634c3http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlhttp://osvdb.org/70463http://roundup.ffmpeg.org/issue2548http://roundup.ffmpeg.org/issue2550http://secunia.com/advisories/42951http://src.chromium.org/viewvc/chrome?view=rev&revision=70200http://www.debian.org/security/2011/dsa-2306http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.securityfocus.com/bid/45788http://www.srware.net/forum/viewtopic.php?f=18&t=2054http://www.ubuntu.com/usn/usn-1104-1/https://exchange.xforce.ibmcloud.com/vulnerabilities/64671https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14380http://article.gmane.org/gmane.comp.video.ffmpeg.devel/122703http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610550http://code.google.com/p/chromium/issues/detail?id=68115http://codereview.chromium.org/5964011http://codereview.chromium.org/6069005http://ffmpeg.mplayerhq.hu/http://git.ffmpeg.org/?p=ffmpeg.git%3Ba=commit%3Bh=13184036a6b1b1d4b61c91118c0896e9ad4634c3http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlhttp://osvdb.org/70463http://roundup.ffmpeg.org/issue2548http://roundup.ffmpeg.org/issue2550http://secunia.com/advisories/42951http://src.chromium.org/viewvc/chrome?view=rev&revision=70200http://www.debian.org/security/2011/dsa-2306http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.securityfocus.com/bid/45788http://www.srware.net/forum/viewtopic.php?f=18&t=2054http://www.ubuntu.com/usn/usn-1104-1/https://exchange.xforce.ibmcloud.com/vulnerabilities/64671https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14380
2011-01-14
Published