LWN.net Logo

libvpx: denial of service

Package(s):libvpx CVE #(s):CVE-2012-0823
Created:February 27, 2012 Updated:February 29, 2012
Description: From the CVE entry:

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".

Alerts:
Mandriva MDVSA-2012:023 2012-02-27
Mandriva MDVSA-2012:023-1 2012-02-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds