CVE-2010-4704 Information

Description

libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.

Reference

http://ffmpeg.mplayerhq.hu/ http://git.ffmpeg.org/?p=ffmpeg.git;a=commit;h=3dde66752d59dfdd0f3727efd66e7202b3c75078 http://secunia.com/advisories/43323 http://www.debian.org/security/2011/dsa-2165 http://www.debian.org/security/2011/dsa-2306 http://www.mandriva.com/security/advisories?name=MDVSA-2011:060 http://www.mandriva.com/security/advisories?name=MDVSA-2011:061 http://www.mandriva.com/security/advisories?name=MDVSA-2011:062 http://www.mandriva.com/security/advisories?name=MDVSA-2011:088 http://www.mandriva.com/security/advisories?name=MDVSA-2011:089 http://www.mandriva.com/security/advisories?name=MDVSA-2011:112 http://www.mandriva.com/security/advisories?name=MDVSA-2011:114 http://www.securityfocus.com/bid/46294 http://www.ubuntu.com/usn/usn-1104-1/ http://www.vupen.com/english/advisories/2011/1241 https://roundup.ffmpeg.org/issue2322

Share on: