FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-0385

This CVE name corresponds to:

Entered Topic
2009-05-17 libxine -- multiple vulnerabilities
2009-03-16 ffmpeg -- 4xm processing memory corruption vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-0385
Phase Assigned(20090202)

Description

Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.

References

Source Reference
BUGTRAQ 20090128 [TKADV2009-004] FFmpeg Type Conversion Vulnerability
MISC http://www.trapkit.de/advisories/TKADV2009-004.txt
CONFIRM http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17
CONFIRM http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&r2=16846&pathrev=16846
CONFIRM http://svn.mplayerhq.hu/ffmpeg?view=rev&revision=16846
DEBIAN DSA-1781
DEBIAN DSA-1782
FEDORA FEDORA-2009-3428
FEDORA FEDORA-2009-3433
GENTOO GLSA-200903-33
MANDRIVA MDVSA-2009:297
UBUNTU USN-734-1
BID 33502
SECUNIA 34296
SECUNIA 34385
SECUNIA 34712
SECUNIA 34905
SECUNIA 34845
VUPEN ADV-2009-0277
OSVDB 51643
SECUNIA 33711
XF ffmpeg-fourxmreadheader-code-execution(48330)