Input validation error in FFmpeg - CVE-2006-4800

 

Input validation error in FFmpeg - CVE-2006-4800

Published: October 30, 2018 / Updated: June 8, 2025


Vulnerability identifier: #VU110621
CSH Severity: Medium
CVSS v4.0:
CVE-ID: CVE-2006-4800
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ffmpeg.sourceforge.net
Affected software:
FFmpeg

Detailed vulnerability description

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c.


How to mitigate CVE-2006-4800

Install update from vendor's website.

Sources