Closed Bug 1209849 Opened 9 years ago Closed 9 years ago

OpenH264: Multiple invalid writes [@WelsDec::BaseMC]

Categories

(Core :: Audio/Video: GMP, defect)

x86_64
Unspecified
defect
Not set
critical

Tracking

()

RESOLVED FIXED

People

(Reporter: tsmith, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: csectype-bounds, sec-critical, testcase)

Attachments

(2 files)

Run with valgrind to reproduce these issues.

Found while fuzzing: https://github.com/cisco/openh264/commit/f9f2bbf805ebb82d0cc46dd79aade2dfb264f046
Attached file valgrind_log.txt
Attached file test_case
Depends on: 1170319
We have fixed this bug in the master branch commit b37cda2 and openh264v1.5 branch commit d6b1680, please help to verify it.
Verified with commit b37cda2482.
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Group: media-core-security → core-security-release
Group: core-security-release
Component: OpenH264 → Audio/Video: GMP
Product: External Software Affecting Firefox → Core
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: