CVE-2010-4704
Publication date 22 January 2011
Last updated 24 July 2024
Ubuntu priority
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | 10.10 maverick |
Fixed 4:0.6-2ubuntu6.1
|
10.04 LTS lucid |
Fixed 4:0.5.1-1ubuntu1.1
|
|
9.10 karmic |
Fixed 4:0.5+svn20090706-2ubuntu2.3
|
|
8.04 LTS hardy |
Fixed 3:0.cvs20070307-5ubuntu7.6
|
|
6.06 LTS dapper | Ignored end of life | |
libav | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |
Patch details
Package | Patch details |
---|---|
ffmpeg | |
libav |
References
Related Ubuntu Security Notices (USN)
- USN-1104-1
- FFmpeg vulnerabilities
- 4 April 2011