Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-0385

Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.116
EPSS Ranking 93.4%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2009-0385
  • Ffmpeg » Ffmpeg » Version: N/A
    cpe:2.3:a:ffmpeg:ffmpeg:-
  • Ffmpeg » Ffmpeg » Version: 0.3
    cpe:2.3:a:ffmpeg:ffmpeg:0.3
  • Ffmpeg » Ffmpeg » Version: 0.3.1
    cpe:2.3:a:ffmpeg:ffmpeg:0.3.1
  • Ffmpeg » Ffmpeg » Version: 0.3.2
    cpe:2.3:a:ffmpeg:ffmpeg:0.3.2
  • Ffmpeg » Ffmpeg » Version: 0.3.3
    cpe:2.3:a:ffmpeg:ffmpeg:0.3.3
  • Ffmpeg » Ffmpeg » Version: 0.3.4
    cpe:2.3:a:ffmpeg:ffmpeg:0.3.4
  • Ffmpeg » Ffmpeg » Version: 0.4.0
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.0
  • Ffmpeg » Ffmpeg » Version: 0.4.2
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.2
  • Ffmpeg » Ffmpeg » Version: 0.4.3
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.3
  • Ffmpeg » Ffmpeg » Version: 0.4.4
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.4
  • Ffmpeg » Ffmpeg » Version: 0.4.5
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.5
  • Ffmpeg » Ffmpeg » Version: 0.4.6
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.6
  • Ffmpeg » Ffmpeg » Version: 0.4.7
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.7
  • Ffmpeg » Ffmpeg » Version: 0.4.8
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.8
  • Ffmpeg » Ffmpeg » Version: 0.4.9
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.9
  • Ffmpeg » Ffmpeg » Version: 0.4.9_pre1
    cpe:2.3:a:ffmpeg:ffmpeg:0.4.9_pre1
  • Ffmpeg » Ffmpeg » Version: 0.5
    cpe:2.3:a:ffmpeg:ffmpeg:0.5
  • Ffmpeg » Ffmpeg » Version: 0.5.1
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.1
  • Ffmpeg » Ffmpeg » Version: 0.5.10
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.10
  • Ffmpeg » Ffmpeg » Version: 0.5.11
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.11
  • Ffmpeg » Ffmpeg » Version: 0.5.12
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.12
  • Ffmpeg » Ffmpeg » Version: 0.5.13
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.13
  • Ffmpeg » Ffmpeg » Version: 0.5.14
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.14
  • Ffmpeg » Ffmpeg » Version: 0.5.15
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.15
  • Ffmpeg » Ffmpeg » Version: 0.5.2
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.2
  • Ffmpeg » Ffmpeg » Version: 0.5.3
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.3
  • Ffmpeg » Ffmpeg » Version: 0.5.4
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.4
  • Ffmpeg » Ffmpeg » Version: 0.5.4.5
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.4.5
  • Ffmpeg » Ffmpeg » Version: 0.5.4.6
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.4.6
  • Ffmpeg » Ffmpeg » Version: 0.5.5
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.5
  • Ffmpeg » Ffmpeg » Version: 0.5.6
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.6
  • Ffmpeg » Ffmpeg » Version: 0.5.7
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.7
  • Ffmpeg » Ffmpeg » Version: 0.5.8
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.8
  • Ffmpeg » Ffmpeg » Version: 0.5.9
    cpe:2.3:a:ffmpeg:ffmpeg:0.5.9
  • Ffmpeg » Ffmpeg » Version: 0.6
    cpe:2.3:a:ffmpeg:ffmpeg:0.6
  • Ffmpeg » Ffmpeg » Version: 0.6.1
    cpe:2.3:a:ffmpeg:ffmpeg:0.6.1
  • Ffmpeg » Ffmpeg » Version: 0.6.2
    cpe:2.3:a:ffmpeg:ffmpeg:0.6.2
  • Canonical » Ubuntu Linux » Version: 7.10
    cpe:2.3:o:canonical:ubuntu_linux:7.10
  • Canonical » Ubuntu Linux » Version: 8.04
    cpe:2.3:o:canonical:ubuntu_linux:8.04
  • Canonical » Ubuntu Linux » Version: 8.10
    cpe:2.3:o:canonical:ubuntu_linux:8.10
  • Debian » Debian Linux » Version: 4.0
    cpe:2.3:o:debian:debian_linux:4.0
  • Debian » Debian Linux » Version: 5.0
    cpe:2.3:o:debian:debian_linux:5.0
  • Debian » Debian Linux » Version: 6.0
    cpe:2.3:o:debian:debian_linux:6.0
  • Fedoraproject » Fedora » Version: 10
    cpe:2.3:o:fedoraproject:fedora:10
  • Fedoraproject » Fedora » Version: 9
    cpe:2.3:o:fedoraproject:fedora:9


Contact Us

Shodan ® - All rights reserved