mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-22 05:46:50 +02:00
754 B
754 B
CVE-2018-12447
Description
The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that leads to a heap-based buffer overflow and remote code execution.
POC
Reference
- https://drive.google.com/open?id=1J3hTt8XHz7u7QDSNYxEuwFZTO6Baggl0
- https://github.com/ebel34/bpg-web-encoder/issues/2
Github
No PoCs found on GitHub currently.