Skip to content

Conversation

@tabudz
Copy link

@tabudz tabudz commented Feb 26, 2025

Description
This PR fixes a security vulnerability in decode_frame() that was cloned from FFmpeg but did not receive the security patch. The original issue was reported and fixed under FFmpeg/FFmpeg@8c2ea30.
This PR applies the same patch to eliminate the vulnerability.

References
https://nvd.nist.gov/vuln/detail/CVE-2017-7862
FFmpeg/FFmpeg@8c2ea30

Fixes: 559/clusterfuzz-testcase-6424225917173760

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant