faad2: arbitrary code execution
| Package(s): | faad2 | CVE #(s): | CVE-2008-4201 | ||||
| Created: | November 12, 2008 | Updated: | November 12, 2008 | ||||
| Description: | From the Gentoo advisory: The ICST-ERCIS (Peking University) reported a heap-based buffer overflow in the decodeMP4file() function in frontend/main.c. A remote attacker could entice a user to open a specially crafted MPEG-4 (MP4) file in an application using FAAD2, possibly leading to the execution of arbitrary code. | ||||||
| Alerts: |
| ||||||
