Input validation error in FFmpeg - CVE-2009-4632

 

Input validation error in FFmpeg - CVE-2009-4632

Published: October 26, 2011 / Updated: June 8, 2025


Vulnerability identifier: #VU110617
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-4632
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read memory contents or crash the application.

oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers to obtain sensitive memory contents and cause a denial of service via a crafted file that triggers an out-of-bounds read.


Affected software

FFmpeg

How to mitigate CVE-2009-4632

Install update from vendor's website.


External References

Related Security Bulletins