Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
CVSS Details
- CVSS 3.1 Base Score: 8.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpegUpgrade mplayer | Jul 30, 2024 | Sep 14, 2006 |
| Ffmpeg | — | Upgrade to FFmpeg version 0.4.9 | Sep 29, 2017 | Sep 14, 2006 |
| Gentoo Linux | — | Upgrade media-video/ffmpeg. | Oct 30, 2017 | Sep 14, 2006 |
| Suse | — | Upgrade libxine1-32bitUpgrade libxine-develUpgrade libxine1-pulseUpgrade libxine1Upgrade libxine1-gnome-vfs | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libxine1Upgrade libavcodec-devUpgrade libxine-main1Upgrade kinoUpgrade libxine1c2 | Nov 8, 2024 | Sep 14, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub