Title: FFmpeg libswscale/utils.c sws_init_context() Function Scale Data Decoding Remote Overflow
Info
Disclosure
Mar 27, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Mar 27, 2012
Description
FFmpeg is prone to an overflow condition. The sws_init_context() function in libswscale/utils.c fails to properly sanitize user-supplied input resulting in an integer overflow. The program does not properly decode certain scale data, allowing a remote attacker to potentially execute arbitrary code.