CVE Vulnerabilities

CVE-2009-0385

Published: Feb 02, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.

Affected Software

NameVendorStart VersionEnd Version
FfmpegFfmpeg*0.6.3 (excluding)
FfmpegUbuntudapper*
FfmpegUbuntugutsy*
FfmpegUbuntuhardy*
FfmpegUbuntuintrepid*
Ffmpeg-debianUbuntuintrepid*
Gstreamer0.10-ffmpegUbuntudapper*
Gstreamer0.10-ffmpegUbuntugutsy*
Gstreamer0.10-ffmpegUbuntuintrepid*
Gstreamer0.10-ffmpegUbuntujaunty*
Gstreamer0.10-ffmpegUbuntukarmic*
MotionUbuntudapper*
MotionUbuntugutsy*
MotionUbuntuintrepid*
MotionUbuntujaunty*
MotionUbuntukarmic*
MplayerUbuntudapper*
MplayerUbuntugutsy*
MplayerUbuntuhardy*
MplayerUbuntuintrepid*
MplayerUbuntujaunty*
SmilutilsUbuntudapper*
SmilutilsUbuntugutsy*
SmilutilsUbuntujaunty*
SmilutilsUbuntukarmic*

References