CVE-2008-4610
mplayer - arbitrary code execution
EPSS 9.3%
描述
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.
如何修補 CVE-2008-4610
要修補 CVE-2008-4610,請將受影響套件升級到下列已修補版本。
- Debian/ffmpeg—升級至 7:2.4.1-1 或更新版本
- Debian/mplayer—升級至 1.0~rc2-20 或更新版本
- Debian/mplayer—升級至 1.0~rc2-17+lenny2 或更新版本
CVE-2008-4610 正在被利用嗎?
中等 — EPSS 為 9.3%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 7:2.4.1-1
- from 0, < 1.0~rc2-20
- from 0, < 1.0~rc2-17+lenny2