In MP4v2 2.0.0, esiste un integer overflow (con conseguente danneggiamento della memoria) durante il ridimensionamento MP4Array per l’atomo ftyp in mp4array.h. |
https://lists.fedoraproject.org/archives/list/[email protected]/message/FRSO2IMK6P7MOIZWGWKONPIEHKBA7WL3/ https://lists.fedoraproject.org/archives/list/[email protected]/message/GISUIWPKBWPXORUFNWBGFTKQS7UUVUC4/ https://lists.fedoraproject.org/archives/list/[email protected]/message/6YCHVOYPIBGM5HYUMQ77KZH2IHSITKVE/ http://www.openwall.com/lists/oss-security/2018/07/16/1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14326 |
Vulnerabilità: CVE-2018-14326
