Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-4048

Опубликовано: 07 дек. 2005
Источник: debian
EPSS Низкий

Описание

Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed0.cvs20050918-5.1package
xmovieremovedpackage
xine-libfixed1.0.1-1.5package
mplayernot-affectedpackage
gst-ffmpegfixed0.8.7-5package
vlcfixed0.8.4.debian-2package

Примечания

  • kino, smilutils, motion and vlc link statically against libavcodec, need a recompile once ffmpeg is fixed

  • smilutils, motion, kino link statically against libavcodec, but don't use the vulnerable function

EPSS

Процентиль: 90%
0.05923
Низкий

Связанные уязвимости

ubuntu
почти 20 лет назад

Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.

nvd
почти 20 лет назад

Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.

github
больше 3 лет назад

Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.

CVSS3: 7.3
fstec
почти 20 лет назад

Уязвимость функции avcodec_default_get_buffer (utils.c) библиотеки Libavcodec из состава мультимедийных библиотек Ffmpeg, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05923
Низкий