CVE-2009-4631: Critical severity FFmpeg FFmpeg vulnerability
Published Feb 10, 2010
·Updated
Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption.
Affected Software
1 affected component
FFmpeg FFmpeg=0.5
Event History
Feb 10, 2010
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4631?
The severity of CVE-2009-4631 is rated as high due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2009-4631?
To fix CVE-2009-4631, upgrade to a later version of FFmpeg that has addressed this vulnerability.
3
What types of attacks can CVE-2009-4631 enable?
CVE-2009-4631 can enable denial of service attacks and potentially execute arbitrary code on the victim's system.
4
Which version of FFmpeg is affected by CVE-2009-4631?
FFmpeg version 0.5 is affected by CVE-2009-4631.
5
How does CVE-2009-4631 exploit an off-by-one error?
CVE-2009-4631 exploits an off-by-one error in the VP3 decoder that can lead to out-of-bounds reads and memory corruption.