Cisco OpenH264 'decode_slice.cpp' Memory Corruption Vulnerability
BID:71467
Info
Cisco OpenH264 'decode_slice.cpp' Memory Corruption Vulnerability
| Bugtraq ID: | 71467 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-8002 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2014 12:00AM |
| Updated: | Dec 05 2014 12:58AM |
| Credit: | Oksana |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco OpenH264 'decode_slice.cpp' Memory Corruption Vulnerability
The Cisco OpenH264 is prone to a memory corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the user running the affected application or result in denial-of-service conditions.
Cisco OpenH264 1.0.0, 1.1.1, and 1.2.2 are vulnerable.
The Cisco OpenH264 is prone to a memory corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the user running the affected application or result in denial-of-service conditions.
Cisco OpenH264 1.0.0, 1.1.1, and 1.2.2 are vulnerable.
Exploit / POC
Cisco OpenH264 'decode_slice.cpp' Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco OpenH264 'decode_slice.cpp' Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco OpenH264 'decode_slice.cpp' Memory Corruption Vulnerability
References:
References:
- Cisco Homepage (Cisco )