[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1125089: [libmpeg2] NULL pointer dereference in mpeg2_init_fbuf() via crafted MPEG video



Package: libmpeg2-4
Version: 0.5.1-9

Hi Debian Security Team,

I would like to report a security vulnerability in the libmpeg2 package.

[Summary]
A NULL pointer dereference vulnerability exists in libmpeg2 0.5.1
that can be triggered by processing a malformed MPEG video stream.

[Affected Package]

[Vulnerability Details]

[Reproduction]
The crash can be triggered using GStreamer's mpeg2dec element:

$ gst-launch-1.0 filesrc location=crash.bin ! mpegvideoparse ! mpeg2dec ! fakesink

The pipeline crashes with SIGSEGV when processing the attached file.

[Proof of Concept]
Attached: libmpeg2_crash_0.bin

[Additional Notes]

As this issue was first identified in GStreamer, we initially reported it
to the GStreamer Security Team. Since the root cause lies within libmpeg2,
we are submitting this report to Debian as well.

Please let me know if you need any additional information.

Best regards,
Wooseok Kim


Attachment: libmpeg2_crash_0.bin
Description: application/macbinary


Reply to: