CVE-2009-0385

Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
ffmpegffmpeg
𝑥
< 0.6.3
debiandebian_linux
4.0
debiandebian_linux
5.0
debiandebian_linux
6.0
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bullseye
7:4.3.7-0+deb11u1
fixed
bullseye (security)
7:4.3.8-0+deb11u1
fixed
bookworm
7:5.1.6-0+deb12u1
fixed
bookworm (security)
7:5.1.6-0+deb12u1
fixed
sid
7:7.1-3
fixed
trixie
7:7.1-3
fixed
mplayer
bullseye
2:1.4+ds1-1+deb11u1
fixed
bookworm
2:1.5+svn38408-1
fixed
sid
2:1.5+svn38542-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
natty
dne
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
ignored
hardy
Fixed 3:0.cvs20070307-5ubuntu7.2
released
gutsy
Fixed 3:0.cvs20070307-5ubuntu4.2
released
dapper
ignored
ffmpeg-debian
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
not-affected
intrepid
Fixed 3:0.svn20080206-12ubuntu3.1
released
hardy
dne
gutsy
dne
dapper
dne
gstreamer0.10-ffmpeg
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
not-affected
gutsy
ignored
dapper
ignored
kino
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
gutsy
not-affected
dapper
not-affected
motion
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
not-affected
gutsy
ignored
dapper
ignored
mplayer
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
ignored
intrepid
ignored
hardy
Fixed 2:1.0~rc2-0ubuntu13.2
released
gutsy
ignored
dapper
ignored
smilutils
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
not-affected
hardy
not-affected
gutsy
ignored
dapper
ignored
References