Input validation error in FFmpeg - CVE-2010-4704
Published: January 23, 2011 / Updated: October 12, 2021
Vulnerability identifier: #VU45419
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2010-4704
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: ffmpeg.sourceforge.net
Affected software:
FFmpeg
FFmpeg
Detailed vulnerability description
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function.
How to mitigate CVE-2010-4704
Install update from vendor's website.
Sources
- http://ffmpeg.mplayerhq.hu/
- http://git.ffmpeg.org/?p=ffmpeg.git;a=commit;h=3dde66752d59dfdd0f3727efd66e7202b3c75078
- http://secunia.com/advisories/43323
- http://www.debian.org/security/2011/dsa-2165
- http://www.debian.org/security/2011/dsa-2306
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:060
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:061
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:062
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:088
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:089
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:112
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:114
- http://www.securityfocus.com/bid/46294
- http://www.ubuntu.com/usn/usn-1104-1/
- http://www.vupen.com/english/advisories/2011/1241
- https://roundup.ffmpeg.org/issue2322