CVE-2008-3162
ffmpeg ffmpeg-debian - arbitrary code execution
EPSS 26.5%
Description
Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.
How to fix CVE-2008-3162
To remediate CVE-2008-3162, upgrade the affected package to a fixed version below.
- Debian/ffmpeg—upgrade to 0.svn20080206-10 or later
- Debian/ffmpeg—upgrade to 0.cvs20060823-8+etch1 or later
- —upgrade to 0.svn20080206-17+lenny1 or later
Is CVE-2008-3162 being exploited?
Moderate — EPSS is 26.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 0.svn20080206-10
- from 0, < 0.cvs20060823-8+etch1
- from 0, < 0.svn20080206-17+lenny1