CVE-2008-4866

Publication date 31 October 2008

Last updated 24 July 2024


Ubuntu priority

Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.

Read the notes from the security team

Status

Package Ubuntu Release Status

Notes


mdeslaur

vulnerable code doesn't seem to exist in gutsy and hardy debian says: [etch] - ffmpeg <not-affected> (Vulnerable code not present) kino is built with --disable-local-ffmpeg, so it's not vulnerable


sbeattie

as of lucid, mplayer uses system ffmpeg rather than embedded version

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details

References

Related Ubuntu Security Notices (USN)

    • USN-734-1
    • FFmpeg vulnerabilities
    • 16 March 2009

Other references