CVE-2008-4201

Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
audiocodingfaad2
𝑥
≤ 2.6.1
audiocodingfaad2
1.1
audiocodingfaad2
2.0:rc1
audiocodingfaad2
2.0:rc2
audiocodingfaad2
2.0:rc3
audiocodingfaad2
2.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
faad2
bullseye
2.10.0-1
fixed
bookworm
2.10.1-1
fixed
sid
2.11.1-1
fixed
trixie
2.11.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
faad2
hardy
Fixed 2.6.1-2ubuntu0.1
released
gutsy
Fixed 2.0.0+cvs20040908+mp4v2+bmp-0ubuntu5.1
released
feisty
Fixed 2.0.0+cvs20040908+mp4v2+bmp-0ubuntu3.7.04.1
released
dapper
Fixed 2.0.0+cvs20040908+mp4v2+bmp-0ubuntu3.6.06.1
released