CVE-2005-4048
Last modified
CVE-2005-4048 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.. EPSS estimates a 5.21% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | 0.4.6 |
| Ffmpeg | Ffmpeg | 0.4.7 |
| Ffmpeg | Ffmpeg | 0.4.8 |
| Ffmpeg | Ffmpeg | 0.4.9 |
| Ffmpeg | Ffmpeg | cvs |
References
- http://secunia.com/advisories/17892Patch, Vendor Advisory
- http://secunia.com/advisories/18066Vendor Advisory
- http://secunia.com/advisories/18087Vendor Advisory
- http://secunia.com/advisories/18107Vendor Advisory
- http://secunia.com/advisories/18400Vendor Advisory
- http://secunia.com/advisories/18739Vendor Advisory
- http://secunia.com/advisories/18746Vendor Advisory
- http://secunia.com/advisories/19114Vendor Advisory
- http://secunia.com/advisories/19192Vendor Advisory
- http://secunia.com/advisories/19272Vendor Advisory
- http://secunia.com/advisories/19279Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2770Vendor Advisory
- http://secunia.com/advisories/17892Patch, Vendor Advisory
- http://secunia.com/advisories/18066Vendor Advisory
- http://secunia.com/advisories/18087Vendor Advisory
- http://secunia.com/advisories/18107Vendor Advisory
- http://secunia.com/advisories/18400Vendor Advisory
- http://secunia.com/advisories/18739Vendor Advisory
- http://secunia.com/advisories/18746Vendor Advisory
- http://secunia.com/advisories/19114Vendor Advisory
- http://secunia.com/advisories/19192Vendor Advisory
- http://secunia.com/advisories/19272Vendor Advisory
- http://secunia.com/advisories/19279Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2770Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4048?
How severe is CVE-2005-4048?
How do I fix CVE-2005-4048?
Are you affected by CVE-2005-4048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
