CVE-2010-4705: Integer Overflow

Published Jan 22, 2011
·
Updated

Integer overflow in the vorbisresiduedecodeinternal function in libavcodec/vorbisdec.c in the Vorbis decoder in FFmpeg, possibly 0.6, has unspecified impact and remote attack vectors, related to the sizes of certain integer data types. NOTE: this might overlap CVE-2011-0480.

Affected Software

1 affected component
FFmpeg FFmpeg=0.6

Event History

Jan 22, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description

Frequently Asked Questions

1

What would an attacker need to do to exploit this issue?

The issue has remote attack vectors and affects the Vorbis decoder. An attacker would need to cause a vulnerable FFmpeg instance to decode crafted Vorbis data.

2

Are systems exposed by default?

Exposure depends on whether the application uses FFmpeg's Vorbis decoder to process attacker-controlled or remotely supplied Vorbis content. The provided data does not identify a specific default configuration.

3

What should teams do if they cannot patch immediately?

Limit or disable processing of untrusted Vorbis content where possible, especially in services that decode media received remotely. The issue is rated critical with impacts to confidentiality, integrity, and availability.

4

How can I determine whether an installation is affected?

Check whether the deployed FFmpeg build includes the vulnerable Vorbis decoder code in libavcodec/vorbis_dec.c and whether the fix associated with commit 366d919016a679d3955f6fe5278fa7ce4f47b81e has been applied. The available information only identifies FFmpeg possibly 0.6, so it does not provide a complete affected-version range.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203