Unrated severityNVD Advisory· Published Nov 1, 2008· Updated Apr 23, 2026
CVE-2008-4866
CVE-2008-4866
Description
Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.
Affected products
14cpe:2.3:a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:ffmpeg:ffmpeg:*:pre1:*:*:*:*:*:*range: <=0.4.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- archives.neohapsis.com/archives/fulldisclosure/2008-09/0103.htmlnvdExploit
- lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016011.htmlnvdExploit
- lists.mplayerhq.hu/pipermail/ffmpeg-cvslog/2008-August/016012.htmlnvdExploit
- secunia.com/advisories/34296nvd
- secunia.com/advisories/34385nvd
- secunia.com/advisories/34845nvd
- security.gentoo.org/glsa/glsa-200903-33.xmlnvd
- www.debian.org/security/2009/dsa-1782nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.openwall.com/lists/oss-security/2008/10/29/6nvd
- www.securityfocus.com/bid/33308nvd
- www.ubuntu.com/usn/USN-734-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46322nvd
News mentions
0No linked articles in our index yet.