|
|
Log in / Subscribe / Register

faad2: arbitrary code execution

Package(s):faad2 CVE #(s):CVE-2008-4201
Created:November 12, 2008 Updated:November 12, 2008
Description:

From the Gentoo advisory:

The ICST-ERCIS (Peking University) reported a heap-based buffer overflow in the decodeMP4file() function in frontend/main.c.

A remote attacker could entice a user to open a specially crafted MPEG-4 (MP4) file in an application using FAAD2, possibly leading to the execution of arbitrary code.

Alerts:
Gentoo 200811-03 faad2 2008-11-09

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds