CVE-2009-4631
Publication date 10 February 2010
Last updated 24 July 2024
Ubuntu priority
Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | 9.10 karmic |
Not affected
|
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
6.06 LTS dapper | Ignored end of life | |
ffmpeg-debian | 9.10 karmic | Not in release |
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |