CVE-2008-4867 describes a critical buffer overflow vulnerability in FFmpeg's libavcodec/dca.c, affecting versions prior to r14917, including its use within MPlayer. This flaw, stemming from an incorrect DCA_MAX_FRAME_SIZE value, allows unauthenticated, context-dependent attackers to achieve complete compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 10.0. Despite its maximum severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.4.9CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:*:pre1:*:*:*:*:*:* | ||
0.3CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:* | ||
0.3.1CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:* | ||
0.3.2CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:* | ||
0.3.3CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities fixed in FFmpeg 0.5
Multiple vulnerabilities fixed in FFmpeg 0.5
Multiple vulnerabilities fixed in FFmpeg 0.5
Multiple vulnerabilities fixed in FFmpeg 0.5
Multiple vulnerabilities fixed in FFmpeg 0.5