twelveand0's Blog
Archive About

February 23, 2017

Ffmpeg-3.2 buffer overflow

Overview A Heap Buffer Overflow vulnerability in FFmpeg-3.2 was found with AFL (http://lcamtuf.coredump.cx/afl/). The vulnerability was trigged when FFmpeg trying to decode an input image (a frame) to a JP2 file. The vulnerability is a Heap Buffer Overflow vulnerability due to some improper out-of-bound access check (in fact, an improper...>

Newer
Older