[FFmpeg-devel] Security issues?

Carl Eugen Hoyos cehoyos
Wed Sep 23 10:20:51 CEST 2009


Michael Niedermayer <michaelni <at> gmx.at> writes:

> 
> On Tue, Sep 22, 2009 at 08:09:08PM +0200, Michael Niedermayer wrote:
> > Hi
> > 
> > lars has mailed me the following 2 links
> >
http://www.heise.de/newsticker/Sicherheitsluecken-in-VLC-und-FFmpeg--/meldung/145655
> > http://secunia.com/advisories/36805/
> 
> infinite loop in aac.c
> chrome patch:
>
http://src.chromium.org/viewvc/chrome/trunk/deps/third_party/ffmpeg/patches/to_upstream/42_aac_zero_bands.patch?revision=25254&view=markup
> 
> aac maintainer please check & apply

This is not on roundup because I was unable to reproduce it with current svn.

Carl Eugen




More information about the ffmpeg-devel mailing list