Impact
libflv库中,flv_parser_append
未检查expect
与bytes
是否处于合理范围,同时FLV_AVHEADER_CODEC
分支缺少default分支导致parser->expect
未被reinit,最终导致溢出发生
Patches
fix flv-parser memory overflow
Workarounds
- 校验expect buffer大小
- 异常flv tag检查
References
@Cossack9989
For more information
If you have any questions or comments about this advisory:
Impact
libflv库中,
flv_parser_append
未检查expect
与bytes
是否处于合理范围,同时FLV_AVHEADER_CODEC
分支缺少default分支导致parser->expect
未被reinit,最终导致溢出发生Patches
fix flv-parser memory overflow
Workarounds
References
@Cossack9989
For more information
If you have any questions or comments about this advisory: