CVE-2006-4800
Summary
| CVE | CVE-2006-4800 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-14 22:07:00 UTC |
| Updated | 2018-10-30 16:25:00 UTC |
| Description | Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ffmpeg | Ffmpeg | 0.4.6 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.7 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.8 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.9 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.6 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.7 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.8 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 0.4.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian update for xine-lib - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Gentoo update for ffmpeg - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mandriva update for xine-lib - Advisories - Secunia | SECUNIA | secunia.com | |
| Security Announcement | SUSE | www.novell.com | |
| DSA-1215 | DEBIAN | www.us.debian.org | |
| Mandriva update for mplayer - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| MPlayer FFmpeg Multiple Buffer Overflow Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Gentoo Bug 133520 - {media-video/ffmpeg|media-libs/xine-lib} multiple issues (CVE-200{5-4048|6-2802}) | MISC | bugs.gentoo.org | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| FFmpeg Multiple Buffer Overflow Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Mandriva update for gstreamer-ffmpeg - Advisories - Secunia | SECUNIA | secunia.com | |
| GStreamer FFmpeg Plug-in Multiple Buffer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Ubuntu update for ffmpeg and xine-lib - Advisories - Secunia | SECUNIA | secunia.com | |
| Mandriva update for ffmpeg - Advisories - Secunia | SECUNIA | secunia.com | |
| xine-lib FFmpeg Multiple Buffer Overflow Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| usn/usn-358-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| FFmpeg Image File Multiple Buffer Overflow Vulnerabilities | BID | www.securityfocus.com | Patch |
| Gentoo Linux Documentation -- FFmpeg: Buffer overflows | GENTOO | security.gentoo.org | Patch, Vendor Advisory |
| SUSE update for mono - Advisories - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.