oss-sec mailing list archives

Re: Re: libav: NULL pointer dereference in put_no_rnd_pixels8_xy2_mmx (rnd_template.c)


From: Agostino Sarubbo <ago () gentoo org>
Date: Sat, 17 Sep 2016 12:50:41 +0200

On Friday 16 September 2016 21:49:19 cve-assign () mitre org wrote:
mpegvideo_motion: Handle edge emulation even without unrestricted_mv

Fix out of bounds read.

libavcodec/mpegvideo_motion.c

Use CVE-2016-7424.

I would like to mention that the upstream git commit is wrong.
This issue is a NULL pointer access and not an out-of-bounds

I already pinged an upstream developer to notify the discrepancy but I guess 
that their git does not allow to edit the message for the commit already 
pushed.

-- 
Agostino Sarubbo
Gentoo Linux Developer


Current thread: