oss-sec mailing list archives

Fastbin double free issue in MP4v2 2.0.0


From: Purushottam Choudhary <Purushottam.Choudhary () kpit com>
Date: Wed, 9 Jan 2019 09:43:17 +0000

Hi,

As per below link Fastbin double free in MP4v2 2.0.0 related issue was reported in opensource community :
https://bugzilla.redhat.com/show_bug.cgi?id=1603294

Issue description : libmp4v2: Double free in the MP4StringProperty class in mp4property.cpp
CVE Number : CVE-2018-14054
CVE status : Not Available

Currently there is no patch is available in the upstream .
Is there any plan for release of the patch or is there any other link in where I can find the patch?

Please let me know.

Thanks & Regards,
Purushottam
This message contains information that may be privileged or confidential and is the property of the KPIT Technologies 
Ltd. It is intended only for the person to whom it is addressed. If you are not the intended recipient, you are not 
authorized to read, print, retain copy, disseminate, distribute, or use this message or any part thereof. If you 
receive this message in error, please notify the sender immediately and delete all copies of this message. KPIT 
Technologies Ltd. does not accept any liability for virus infected mails.


Current thread: