Closed Bug 1192929 Opened 9 years ago Closed 9 years ago

Openh264: heap-use-after-free [@WelsDec::WelsReorderRefList]

Categories

(Core :: Audio/Video: GMP, defect)

defect
Not set
critical

Tracking

()

RESOLVED FIXED

People

(Reporter: tsmith, Unassigned)

References

(Blocks 1 open bug)

Details

(4 keywords)

Attachments

(3 files, 1 obsolete file)

Attached file call_stack.txt (obsolete) —
No description provided.
Attached file test_case.264
See Also: → 1192947
What codebase is this being reported against? 1.4 as is currently being shipped, or OpenH264 trunk?
Flags: needinfo?(twsmith)
(In reply to Randell Jesup [:jesup] from comment #2) > What codebase is this being reported against? 1.4 as is currently being > shipped, or OpenH264 trunk? This was found while fuzzing trunk. I could not reproduce it on 1.4 with this test case.
Flags: needinfo?(twsmith)
Depends on: 1170319
Keywords: sec-high
It is caused by the recently modification and we have fixed it in latest code, please help to check it.
Attached file call_stack.txt
Attachment #8645805 - Attachment is obsolete: true
Attached file test_case.264
Group: core-security → media-core-security
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Group: media-core-security → core-security-release
Group: core-security-release
Component: OpenH264 → Audio/Video: GMP
Product: External Software Affecting Firefox → Core
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: