CVE-2009-0385
Publication date 2 February 2009
Last updated 24 July 2024
Ubuntu priority
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | ||
ffmpeg-debian | ||
gstreamer0.10-ffmpeg | ||
kino | ||
motion | ||
mplayer | ||
smilutils | ||
Notes
Patch details
Package | Patch details |
---|---|
ffmpeg | |
ffmpeg-debian | |
mplayer |
References
Related Ubuntu Security Notices (USN)
- USN-734-1
- FFmpeg vulnerabilities
- 16 March 2009