Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ffmpeg | Ffmpeg | * | 0.6.3 (excluding) |
| Ffmpeg | Ubuntu | dapper | * |
| Ffmpeg | Ubuntu | gutsy | * |
| Ffmpeg | Ubuntu | hardy | * |
| Ffmpeg | Ubuntu | intrepid | * |
| Ffmpeg-debian | Ubuntu | intrepid | * |
| Gstreamer0.10-ffmpeg | Ubuntu | dapper | * |
| Gstreamer0.10-ffmpeg | Ubuntu | gutsy | * |
| Gstreamer0.10-ffmpeg | Ubuntu | intrepid | * |
| Gstreamer0.10-ffmpeg | Ubuntu | jaunty | * |
| Gstreamer0.10-ffmpeg | Ubuntu | karmic | * |
| Motion | Ubuntu | dapper | * |
| Motion | Ubuntu | gutsy | * |
| Motion | Ubuntu | intrepid | * |
| Motion | Ubuntu | jaunty | * |
| Motion | Ubuntu | karmic | * |
| Mplayer | Ubuntu | dapper | * |
| Mplayer | Ubuntu | gutsy | * |
| Mplayer | Ubuntu | hardy | * |
| Mplayer | Ubuntu | intrepid | * |
| Mplayer | Ubuntu | jaunty | * |
| Smilutils | Ubuntu | dapper | * |
| Smilutils | Ubuntu | gutsy | * |
| Smilutils | Ubuntu | jaunty | * |
| Smilutils | Ubuntu | karmic | * |