First published: Wed Dec 07 2005(Updated: )
Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =0.4.6 | |
FFmpeg | =0.4.7 | |
FFmpeg | =0.4.8 | |
FFmpeg | =0.4.9 | |
FFmpeg | =cvs |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4048 has been rated as a critical vulnerability due to the potential for remote code execution.
To mitigate CVE-2005-4048, upgrade to a version of FFmpeg that is later than 0.4.9-pre1.
CVE-2005-4048 affects FFmpeg versions 0.4.6 through 0.4.9 and can also impact products that use FFmpeg like mplayer and xine-lib.
CVE-2005-4048 allows remote attackers to execute arbitrary commands through specially crafted small PNG images.
No, CVE-2005-4048 is primarily exploited through processing malicious PNG files received over the network.