Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 10 Jul 2008 00:50:44 +1000
From: Steffen Joeris <steffen.joeris@...lelinux.de>
To: oss-security@...ts.openwall.com
Subject: CVE id request: libavformat

Hi

There is a possible DoS in libavformat.

mplayer bugreport:
https://roundup.mplayerhq.hu/roundup/ffmpeg/issue311

The quote from the bugreport:
This has audio sectors mixed in with video sectors, so the check at 
psxstr.c:319 copies them onto the end of the video packet, going past 
the end of the buffer.

Upstream patch:
http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/psxstr.c?r1=13993&r2=13992&pathrev=13993

Debian bugreport:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=489965

Could I get a CVE id for this?

Cheers
Steffen

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ