CVE-2018-14326

Name
CVE-2018-14326
Description
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit http://www.openwall.com/lists/oss-security/2018/07/16/1
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6YCHVOYPIBGM5HYUMQ77KZH2IHSITKVE/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRSO2IMK6P7MOIZWGWKONPIEHKBA7WL3/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GISUIWPKBWPXORUFNWBGFTKQS7UUVUC4/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:techsmith:mp4v2:2.0.0:*:*:*:*:*:*:* mp4v2 == None == 2.0.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status