CVE-2009-0385
Publication date 2 February 2009
Last updated 24 July 2024
Ubuntu priority
Description
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ffmpeg | ||
| ffmpeg-debian | ||
| gstreamer0.10-ffmpeg | ||
| kino | ||
| motion | ||
| mplayer | ||
| smilutils | ||
Notes
Patch details
| Package | Patch details |
|---|---|
| ffmpeg | |
| ffmpeg-debian | |
| mplayer |
References
Related Ubuntu Security Notices (USN)
- USN-734-1
- FFmpeg vulnerabilities
- 16 March 2009