6.8
CVSSv2

CVE-2010-3429

Published: 30/09/2010 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

flicvideo.c in libavcodec 0.6 and previous versions in FFmpeg, as used in MPlayer and other products, allows remote malicious users to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg libavcodec

ffmpeg ffmpeg

ffmpeg ffmpeg 0.3

ffmpeg ffmpeg 0.3.1

ffmpeg ffmpeg 0.3.2

ffmpeg ffmpeg 0.3.3

ffmpeg ffmpeg 0.3.4

ffmpeg ffmpeg 0.4.0

ffmpeg ffmpeg 0.4.2

ffmpeg ffmpeg 0.4.3

ffmpeg ffmpeg 0.4.4

ffmpeg ffmpeg 0.4.5

ffmpeg ffmpeg 0.4.6

ffmpeg ffmpeg 0.4.7

ffmpeg ffmpeg 0.4.8

ffmpeg ffmpeg 0.4.9

ffmpeg ffmpeg 0.5

mplayerhq mplayer

mplayerhq mplayer 0.01

mplayerhq mplayer 0.02

mplayerhq mplayer 0.05

mplayerhq mplayer 0.06

mplayerhq mplayer 0.07

mplayerhq mplayer 0.08

mplayerhq mplayer 0.09

mplayerhq mplayer 0.10

mplayerhq mplayer 0.11

mplayerhq mplayer 0.17_idegcounter

mplayerhq mplayer 0.17a_idegcounter

mplayerhq mplayer 0.18

mplayerhq mplayer 0.50

mplayerhq mplayer 0.60

mplayerhq mplayer 0.90

mplayerhq mplayer 0.91

mplayerhq mplayer 0.92

mplayerhq mplayer 0.92.1

mplayerhq mplayer 0.93

mplayerhq mplayer 1.0

Vendor Advisories

FFmpeg could be made to run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #598590 CVE-2010-3249: FLIC vulnerabiliry Package: ffmpeg; Maintainer for ffmpeg is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for ffmpeg is src:ffmpeg (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Thu, 30 Sep 2010 10:1 ...
Debian Bug report logs - #628448 several vulnerabilities: CVE-2011-2162 CVE-2011-2161 CVE-2011-2160 Package: libav; Maintainer for libav is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Steffen Joeris <white@debianorg> Date: Sun, 29 May 2011 03:27:01 UTC Severity: g ...
Several vulnerabilities have been discovered in FFmpeg coders, which are used by MPlayer and other applications CVE-2010-3429 Cesar Bernardini and Felipe Andres Manzano reported an arbitrary offset dereference vulnerability in the libavcodec, in particular in the FLIC file format parser A specific FLIC file may exploit this vulnerability a ...