CVE-2010-4704
CVE-2010-4704
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://ffmpeg.mplayerhq.hu/http://git.ffmpeg.org/?p=ffmpeg.git%3Ba=commit%3Bh=3dde66752d59dfdd0f3727efd66e7202b3c75078http://secunia.com/advisories/43323https://roundup.ffmpeg.org/issue2322http://www.debian.org/security/2011/dsa-2165http://www.debian.org/security/2011/dsa-2306http://www.mandriva.com/security/advisories?name=MDVSA-2011:060http://www.mandriva.com/security/advisories?name=MDVSA-2011:061http://www.mandriva.com/security/advisories?name=MDVSA-2011:062http://www.mandriva.com/security/advisories?name=MDVSA-2011:088http://www.mandriva.com/security/advisories?name=MDVSA-2011:089http://www.mandriva.com/security/advisories?name=MDVSA-2011:112