First published: Thu Sep 14 2006(Updated: )
Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xine | =1.1.0 | |
xine | <=1.1.1 | |
xine | =1.0.1 | |
xine | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4799 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2006-4799, upgrade xine-lib to version 1.1.2 or later.
CVE-2006-4799 affects xine-lib versions prior to 1.1.2, including 1.1.0 and up to 1.1.1.
CVE-2006-4799 is a buffer overflow vulnerability.
Yes, CVE-2006-4799 can be exploited via crafted AVI files with bad indexes.