First published: Fri Oct 31 2008(Updated: )
Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=0.4.9 | |
FFmpeg | =0.3 | |
FFmpeg | =0.3.1 | |
FFmpeg | =0.3.2 | |
FFmpeg | =0.3.3 | |
FFmpeg | =0.3.4 | |
FFmpeg | =0.4.0 | |
FFmpeg | =0.4.2 | |
FFmpeg | =0.4.3 | |
FFmpeg | =0.4.4 | |
FFmpeg | =0.4.5 | |
FFmpeg | =0.4.6 | |
FFmpeg | =0.4.7 | |
FFmpeg | =0.4.8 | |
JW Player |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4867 has a high severity due to the potential for buffer overflow attacks.
To fix CVE-2008-4867, upgrade to a version of FFmpeg later than 0.4.9 or apply the appropriate patches.
CVE-2008-4867 affects FFmpeg versions up to and including 0.4.9.
MPlayer itself is not directly affected by CVE-2008-4867, but it utilizes the vulnerable FFmpeg versions.
CVE-2008-4867 is caused by a buffer overflow in the libavcodec/dca.c component of FFmpeg, specifically related to the DCA_MAX_FRAME_SIZE value.