CVE-2010-4704
EPSS 4.1%
Description
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-0480.
How to fix CVE-2010-4704
To remediate CVE-2010-4704, upgrade the affected package to a fixed version below.
- Debian/ffmpeg—upgrade to 7:2.4.1-1 or later
Is CVE-2010-4704 being exploited?
Low — EPSS is 4.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 7:2.4.1-1