CVE-2009-4640: Medium severity FFmpeg FFmpeg vulnerability
Array index error in vorbisdec.c in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Vorbis file that triggers an out-of-bounds read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4640?
CVE-2009-4640 is classified as a high severity vulnerability due to its potential to cause a denial of service and arbitrary code execution.
How do I fix CVE-2009-4640?
The best way to fix CVE-2009-4640 is to upgrade to a later version of FFmpeg that addresses the vulnerability.
What type of attack does CVE-2009-4640 facilitate?
CVE-2009-4640 facilitates denial of service attacks and potentially allows for arbitrary code execution via crafted Vorbis files.
Which versions of FFmpeg are affected by CVE-2009-4640?
CVE-2009-4640 specifically affects FFmpeg version 0.5.
What is the impact of exploiting CVE-2009-4640?
Exploiting CVE-2009-4640 can lead to application crashes and may allow attackers to run arbitrary commands on the affected system.