CVE-2009-4635 describes a critical vulnerability in FFmpeg 0.5, where a specially crafted MOV container with malformed tags can lead to a denial of service and potentially arbitrary code execution. The vulnerability stems from inconsistent codec type handling, causing a video-structure pointer to be processed by the MP3 decoder, resulting in a stack-based buffer overflow. With a CVSS score of 9.3, this vulnerability is highly severe, allowing unauthenticated remote attackers to achieve complete compromise (confidentiality, integrity, availability) with medium attack complexity. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.