[CVE-2008-4201] faad2 2.6.1 - Heap-based buffer overflow in the decodeMP4file function and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file
Bug #277110 reported by
Stefan Lesicnik
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
faad2 (Ubuntu) |
Fix Released
|
Undecided
|
William Grant | ||
Dapper |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Feisty |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Gutsy |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Hardy |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Intrepid |
Fix Released
|
Undecided
|
William Grant |
Bug Description
CVE-2008-4201
Description
Heap-based buffer overflow in the decodeMP4file function (frontend/main.c)
in FAAD2 before 2.6.1 allows remote attackers to cause a denial of service
(crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4)
file.
References
http://
Changed in faad2: | |
assignee: | nobody → wgrant |
status: | New → In Progress |
Changed in faad2: | |
assignee: | nobody → stefanlsd |
status: | New → In Progress |
assignee: | nobody → stefanlsd |
status: | New → In Progress |
assignee: | nobody → stefanlsd |
status: | New → In Progress |
assignee: | nobody → stefanlsd |
status: | New → In Progress |
Changed in faad2: | |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
Changed in faad2: | |
status: | Fix Committed → Fix Released |
Changed in faad2: | |
status: | In Progress → Fix Released |
To post a comment you must log in.
Intrepid sync request has been requested. /bugs.edge. launchpad. net/ubuntu/ +source/ faad2/+ bug/275311
https:/
Thanks William.