CVE-2009-4637
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 17%
from disclosure to weapon0 days
Published on NVDFeb 10
1st PoCSep 21
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/33233⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://scarybeastsecurity.blogspot.com/2009/09/patching-ffmpeg-into-shape.htmlhttp://secunia.com/advisories/36805http://secunia.com/advisories/38643http://secunia.com/advisories/39482https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240http://www.debian.org/security/2010/dsa-2000http://www.securityfocus.com/bid/36465http://www.ubuntu.com/usn/USN-931-1http://www.vupen.com/english/advisories/2010/0935