CVE-2008-4867

Publication date 31 October 2008

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.

Read the notes from the security team

Status

Package Ubuntu Release Status

Notes


mdeslaur

kino is built with --disable-local-ffmpeg, so it's not vulnerable

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details

References

Related Ubuntu Security Notices (USN)

    • USN-734-1
    • FFmpeg vulnerabilities
    • 16 March 2009

Other references