summaryrefslogtreecommitdiff
path: root/src/libmpeg2/motion_comp.c
diff options
context:
space:
mode:
authorMatthias Hopf <mhopf@suse.de>2009-01-04 17:21:46 +0000
committerMatthias Hopf <mhopf@suse.de>2009-01-04 17:21:46 +0000
commitde3b12bc7488ca43834f2840619744a9ec2c5b16 (patch)
treeddf1aefd735fa835ba9307dcdd030f51c72c42b5 /src/libmpeg2/motion_comp.c
parentba5f2ab8d7209f3971ecf22ea3bc5ee43a692b5c (diff)
downloadxine-lib-de3b12bc7488ca43834f2840619744a9ec2c5b16.tar.gz
xine-lib-de3b12bc7488ca43834f2840619744a9ec2c5b16.tar.bz2
Fix for CVE-2008-5243.
The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote attackers to cause a denial of service (crash) via a crafted value, probably an array index error.
Diffstat (limited to 'src/libmpeg2/motion_comp.c')
0 files changed, 0 insertions, 0 deletions