CVE-2008-4201

Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:audiocoding:faad2:*:*:*:*:*:*:*:*
cpe:2.3:a:audiocoding:faad2:1.1:*:*:*:*:*:*:*
cpe:2.3:a:audiocoding:faad2:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:audiocoding:faad2:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:audiocoding:faad2:2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:audiocoding:faad2:2.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:51

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499899 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499899 -
References () http://bugs.gentoo.org/attachment.cgi?id=166174&action=view - Exploit () http://bugs.gentoo.org/attachment.cgi?id=166174&action=view - Exploit
References () http://bugs.gentoo.org/show_bug.cgi?id=238445 - () http://bugs.gentoo.org/show_bug.cgi?id=238445 -
References () http://osvdb.org/48349 - () http://osvdb.org/48349 -
References () http://secunia.com/advisories/32006 - Vendor Advisory () http://secunia.com/advisories/32006 - Vendor Advisory
References () http://secunia.com/advisories/32661 - Vendor Advisory () http://secunia.com/advisories/32661 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200811-03.xml - () http://security.gentoo.org/glsa/glsa-200811-03.xml -
References () http://www.audiocoding.com/archive.html - () http://www.audiocoding.com/archive.html -
References () http://www.audiocoding.com/patch/main_overflow.diff - () http://www.audiocoding.com/patch/main_overflow.diff -
References () http://www.openwall.com/lists/oss-security/2008/09/24/6 - () http://www.openwall.com/lists/oss-security/2008/09/24/6 -
References () http://www.securityfocus.com/bid/31219 - () http://www.securityfocus.com/bid/31219 -
References () http://www.vupen.com/english/advisories/2008/2601 - Vendor Advisory () http://www.vupen.com/english/advisories/2008/2601 - Vendor Advisory

Information

Published : 2008-09-24 11:42

Updated : 2024-11-21 00:51


NVD link : CVE-2008-4201

Mitre link : CVE-2008-4201

CVE.ORG link : CVE-2008-4201


JSON object : View

Products Affected

audiocoding

  • faad2
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer