CVE-2010-4704: Input Validation
Published Jan 22, 2011
·Updated
libavcodec/vorbisdec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbisfloor0decode function. NOTE: this might overlap CVE-2011-0480.
Affected Software
17 affected components
FFmpeg FFmpeg<=0.6.1
FFmpeg FFmpeg=0.3
FFmpeg FFmpeg=0.3.1
FFmpeg FFmpeg=0.3.2
FFmpeg FFmpeg=0.3.3
FFmpeg FFmpeg=0.3.4
FFmpeg FFmpeg=0.4.0
FFmpeg FFmpeg=0.4.2
FFmpeg FFmpeg=0.4.3
FFmpeg FFmpeg=0.4.4
FFmpeg FFmpeg=0.4.5
FFmpeg FFmpeg=0.4.6
FFmpeg FFmpeg=0.4.7
FFmpeg FFmpeg=0.4.8
FFmpeg FFmpeg=0.4.9-pre1
FFmpeg FFmpeg=0.5
FFmpeg FFmpeg=0.6
Remediation
Event History
Jan 22, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4704?
CVE-2010-4704 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2010-4704?
To fix CVE-2010-4704, update to the latest version of FFmpeg beyond 0.6.1.
3
Which versions of FFmpeg are affected by CVE-2010-4704?
FFmpeg versions 0.6.1 and earlier are affected by CVE-2010-4704.
4
Can CVE-2010-4704 be exploited remotely?
Yes, CVE-2010-4704 can be exploited by remote attackers through crafted .ogg files.
5
What function is associated with CVE-2010-4704?
CVE-2010-4704 is related to the vorbis_floor0_decode function in the Vorbis decoder of FFmpeg.