Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pmw-9j92-3c4c

Опубликовано: 24 фев. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.6

Описание

OpenH264 Rust API Openh264 Decoding Functions Heap Overflow Vulnerability

OpenH264 recently reported a heap overflow that was fixed in upstream 63db555 and integrated into our 0.6.6 release. For users relying on Cisco's pre-compiled DLL, we also published 0.8.0, which is compatible with their latest fixed DLL version 2.6.0.

In other words:

  • if you rely on our source feature only, >=0.6.6 should be safe,
  • if you rely on libloading, you must upgrade to 0.8.0 and use their latest DLL >=2.6.0.

Users handling untrusted video files should update immediately.

Пакеты

Наименование

openh264-sys2

rust
Затронутые версииВерсия исправления

< 0.8.0

0.8.0

8.6 High

CVSS4

Дефекты

CWE-122
CWE-1395

8.6 High

CVSS4

Дефекты

CWE-122
CWE-1395