Back to Database
Status published
Medium
CVE-2009-4639
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5...
Vulnerability Description
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4639
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:088
- http://secunia.com/advisories/36805
- http://www.securityfocus.com/bid/36465
- http://secunia.com/advisories/39482
- https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:061
- https://roundup.ffmpeg.org/roundup/ffmpeg/issue1245
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:112
- http://scarybeastsecurity.blogspot.com/2009/09/patching-ffmpeg-into-shape.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:059
- http://www.vupen.com/english/advisories/2011/1241
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:060
- http://www.ubuntu.com/usn/USN-931-1
- http://www.vupen.com/english/advisories/2010/0935
More from ffmpeg
View All →CVE-2022-48434
libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and...
Unknown
0
CVE-2021-38291
FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion...
High
7.5
CVE-2021-38171
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the...
Critical
9.8
CVE-2021-38114
libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value...
Medium
5.5
CVE-2021-38094
Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg...
High
8.8
Affected Vendor
ffmpeg
View all reports →Affected Software
ffmpeg
Vulnerable Versions:
0.5
Timeline
Official Publish:
February 10th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.