Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 150265 - <media-video/ffmpeg-0.4.9_p20060530 - multiple buffer overflows in libavcodec (CVE-2006-4800)
Summary: <media-video/ffmpeg-0.4.9_p20060530 - multiple buffer overflows in libavcodec...
Status: RESOLVED DUPLICATE of bug 133520
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-06 06:29 UTC by Carsten Lohrke (RETIRED)
Modified: 2006-10-06 06:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2006-10-06 06:29:10 UTC
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.


http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4800


I guess at least xine will be affected as well(?). Also some architecture have only older ffmpeg versions keyworded/stable.
Comment 1 Diego Elio Pettenò (RETIRED) gentoo-dev 2006-10-06 06:42:17 UTC

*** This bug has been marked as a duplicate of 133520 ***