Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4610
HistoryOct 20, 2008 - 12:00 a.m.

CVE-2008-4610

2008-10-2000:00:00
ubuntu.com
ubuntu.com
10

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.141 Low

EPSS

Percentile

95.7%

MPlayer allows remote attackers to cause a denial of service (application
crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2)
a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm,
different vectors than CVE-2007-6718.

Notes

Author Note
mdeslaur First issue is the same as CVE-2008-5244, but for mplayer The ogm issue is a ffmpeg problem. Just a crasher.
sbeattie according to debian, first issue is actually a crash in libfaad2, though earlier mplayer didn’t link against system libfaad2 examining packages, 2:1.0~rc4.dfsg1+svn33713-1 appears to be the first one that links against system libfaad
OSVersionArchitecturePackageVersionFilename
ubuntu7.10noarchffmpeg< 3:0.cvs20070307-5ubuntu4.2UNKNOWN
ubuntu8.04noarchffmpeg< 3:0.cvs20070307-5ubuntu7.2UNKNOWN
ubuntu8.10noarchffmpeg-debian< 3:0.svn20080206-12ubuntu3.1UNKNOWN

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.141 Low

EPSS

Percentile

95.7%