[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-4704Date: (C)2011-01-22   (M)2023-12-22


libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECUNIA-43323
BID-46294
ADV-2011-1241
DSA-2165
DSA-2306
MDVSA-2011:060
MDVSA-2011:061
MDVSA-2011:062
MDVSA-2011:088
MDVSA-2011:089
MDVSA-2011:112
MDVSA-2011:114
USN-1104-1
http://ffmpeg.mplayerhq.hu/
http://git.ffmpeg.org/?p=ffmpeg.git%3Ba=commit%3Bh=3dde66752d59dfdd0f3727efd66e7202b3c75078
https://roundup.ffmpeg.org/issue2322

CPE    17
cpe:/a:ffmpeg:ffmpeg:0.3
cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1
cpe:/a:ffmpeg:ffmpeg:0.5
cpe:/a:ffmpeg:ffmpeg:0.6
...
CWE    1
CWE-20
OVAL    10
oval:org.secpod.oval:def:300434
oval:org.secpod.oval:def:300431
oval:org.secpod.oval:def:300437
oval:org.secpod.oval:def:301042
...

© SecPod Technologies