Vulnerability Name:

CVE-2010-4704 (CCN-64671)

Assigned:2011-01-12
Published:2011-01-12
Updated:2011-10-26
Summary:libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function.
Note: this might overlap CVE-2011-0480.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2010-4704

Source: MITRE
Type: CNA
CVE-2010-4705

Source: MITRE
Type: CNA
CVE-2011-0480

Source: CONFIRM
Type: UNKNOWN
http://ffmpeg.mplayerhq.hu/

Source: CONFIRM
Type: Patch
http://git.ffmpeg.org/?p=ffmpeg.git;a=commit;h=3dde66752d59dfdd0f3727efd66e7202b3c75078

Source: CCN
Type: Google Chrome Releases Web site
Chrome Stable Release

Source: CCN
Type: SA42850
Google Chrome Multiple Vulnerabilities

Source: CCN
Type: SA42951
SRWare Iron Multiple Vulnerabilities

Source: CCN
Type: SA43197
FFmpeg Vorbis Decoder Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
43323

Source: DEBIAN
Type: UNKNOWN
DSA-2165

Source: DEBIAN
Type: UNKNOWN
DSA-2306

Source: DEBIAN
Type: DSA-2165
ffmpeg-debian -- buffer overflow

Source: DEBIAN
Type: DSA-2306
ffmpeg -- several vulnerabilities

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:060

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:061

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:062

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:088

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:089

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:112

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2011:114

Source: CCN
Type: OSVDB ID: 70463
FFmpeg Vorbis Decoder vorbis_dec.c WebM File Handling Multiple Overflow DoS

Source: CCN
Type: OSVDB ID: 70650
FFmpeg Vorbis Decoder libavcodec/vorbis_dec.c vorbis_floor0_decode Function OGG File Handling Remote DoS

Source: CCN
Type: OSVDB ID: 70651
FFmpeg Vorbis Decoder libavcodec/vorbis_dec.c vorbis_residue_decode_internal Function Overflow

Source: CCN
Type: BID-45788
Google Chrome prior to 8.0.552.237 Multiple Security Vulnerabilities

Source: BID
Type: UNKNOWN
46294

Source: CCN
Type: BID-46294
FFmpeg Integer Overflow and Denial of Service Vulnerabilities

Source: CCN
Type: BID-47154
FFmpeg Vorbis Decoder 'vorbis_dec.c' Multiple Buffer Overflow Vulnerabilities

Source: UBUNTU
Type: UNKNOWN
USN-1104-1

Source: VUPEN
Type: UNKNOWN
ADV-2011-1241

Source: XF
Type: UNKNOWN
chrome-vorbis-bo(64671)

Source: CONFIRM
Type: Exploit
https://roundup.ffmpeg.org/issue2322

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ffmpeg:ffmpeg:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* (Version <= 0.6.1)

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows:server_2003:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:server_2003:sp2:itanium:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:server_2003:sp2:x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:*
  • OR cpe:/o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_vista:-:sp1:x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:itanium:*
  • OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*
  • OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_vista:-:sp2:x64:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows_7:-:-:*:*:ultimate_n:*:x64:*
  • OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:x32:*
  • OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*
  • OR cpe:/a:google:chrome:8.0.549.0:*:*:*:*:*:*:*
  • OR cpe:/a:google:chrome:8.0.550.0:*:*:*:*:*:*:*
  • OR cpe:/a:google:chrome:8.0.551.0:*:*:*:*:*:*:*
  • OR cpe:/a:google:chrome:8.0.552.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ffmpeg:ffmpeg:0.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.4.9:*:*:*:*:*:*:*
  • OR cpe:/a:ffmpeg:ffmpeg:0.8.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:13661
    P
    USN-1104-1 -- ffmpeg vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:12955
    P
    DSA-2165-1 ffmpeg-debian -- buffer overflow
    2014-06-23
    oval:org.mitre.oval:def:15128
    P
    DSA-2306-1 ffmpeg -- several
    2014-06-23
    BACK
    ffmpeg ffmpeg 0.3
    ffmpeg ffmpeg 0.3.1
    ffmpeg ffmpeg 0.3.2
    ffmpeg ffmpeg 0.3.3
    ffmpeg ffmpeg 0.3.4
    ffmpeg ffmpeg 0.4.0
    ffmpeg ffmpeg 0.4.2
    ffmpeg ffmpeg 0.4.3
    ffmpeg ffmpeg 0.4.4
    ffmpeg ffmpeg 0.4.5
    ffmpeg ffmpeg 0.4.6
    ffmpeg ffmpeg 0.4.7
    ffmpeg ffmpeg 0.4.8
    ffmpeg ffmpeg 0.4.9 pre1
    ffmpeg ffmpeg 0.5
    ffmpeg ffmpeg 0.6
    ffmpeg ffmpeg *
    microsoft windows server_2003 sp2
    microsoft windows server_2003 sp2
    microsoft windows server_2003 sp2
    microsoft windows xp sp2
    microsoft windows vista - sp1
    microsoft windows vista - sp1
    microsoft windows server 2008 -
    microsoft windows server 2008 -
    microsoft windows server 2008 -
    microsoft windows xp sp3
    microsoft windows vista - sp2
    microsoft windows vista - sp2
    microsoft windows server 2008 sp2
    microsoft windows server 2008 sp2
    microsoft windows 7 -
    microsoft windows 7 -
    microsoft windows server 2008 - r2
    microsoft windows server 2008 r2
    microsoft windows server 2008
    google chrome 8.0.549.0
    google chrome 8.0.550.0
    google chrome 8.0.551.0
    google chrome 8.0.552.0
    ffmpeg ffmpeg 0.4.8
    ffmpeg ffmpeg 0.4.7
    ffmpeg ffmpeg 0.4.6
    ffmpeg ffmpeg 0.4.9
    ffmpeg ffmpeg 0.8.7