[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-734-1 -- ffmpeg, ffmpeg-debian vulnerabilities

ID: oval:org.secpod.oval:def:700346Date: (C)2011-05-13   (M)2023-11-09
Class: PATCHFamily: unix




It was discovered that FFmpeg did not correctly handle certain malformed Ogg Media files. If a user were tricked into opening a crafted Ogg Media file, an attacker could cause the application using FFmpeg to crash, leading to a denial of service. It was discovered that FFmpeg did not correctly handle certain parameters when creating DTS streams. If a user were tricked into processing certain commands, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 8.10. It was discovered that FFmpeg did not correctly handle certain malformed DTS Coherent Acoustics files. If a user were tricked into opening a crafted DCA file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. It was discovered that FFmpeg did not correctly handle certain malformed 4X movie files. If a user were tricked into opening a crafted 4xm file, an attacker could execute arbitrary code with the privileges of the user invoking the program

Platform:
Ubuntu 7.10
Ubuntu 8.10
Ubuntu 8.04
Product:
ffmpeg
Reference:
USN-734-1
CVE-2008-4610
CVE-2008-4866
CVE-2008-4867
CVE-2009-0385
CVE    4
CVE-2008-4610
CVE-2008-4866
CVE-2008-4867
CVE-2009-0385
...
CPE    3
cpe:/o:ubuntu:ubuntu_linux:8.04
cpe:/o:ubuntu:ubuntu_linux:7.10
cpe:/o:ubuntu:ubuntu_linux:8.10

© SecPod Technologies