CVE-2005-4048: Buffer Overflow
Heap-based buffer overflow in the avcodecdefaultgetbuffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4048?
CVE-2005-4048 has been rated as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2005-4048?
To mitigate CVE-2005-4048, upgrade to a version of FFmpeg that is later than 0.4.9-pre1.
What software is affected by CVE-2005-4048?
CVE-2005-4048 affects FFmpeg versions 0.4.6 through 0.4.9 and can also impact products that use FFmpeg like mplayer and xine-lib.
What type of attack does CVE-2005-4048 enable?
CVE-2005-4048 allows remote attackers to execute arbitrary commands through specially crafted small PNG images.
Can CVE-2005-4048 be exploited through locally stored files?
No, CVE-2005-4048 is primarily exploited through processing malicious PNG files received over the network.