CVE-2006-4800
EPSS 6.3%
Description
Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
How to fix CVE-2006-4800
To remediate CVE-2006-4800, upgrade the affected package to a fixed version below.
- Debian/ffmpeg—upgrade to 0.cvs20060329-1 or later
- —upgrade to 1.0~rc1-1 or later
Is CVE-2006-4800 being exploited?
Moderate — EPSS is 6.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.cvs20060329-1
- from 0, < 1.0~rc1-1