CVE ID | CVE-2014-8001 |
CVSS SCORE | 9.5, AV:U/AC:L/Au:U/C:P/I:P/A:P |
AFFECTED VENDORS |
Cisco |
AFFECTED PRODUCTS |
OpenH264 |
VULNERABILITY DETAILS |
The specific flaw exists within the decoder logic. By providing malformed H.264 data to the decoder, an attacker can overwrite a heap buffer. This could result in the execution of arbitrary code in the context of the application. |
ADDITIONAL DETAILS |
Cisco has issued an update to correct this vulnerability. More details can be found at:
http://tools.cisco.com/security/center/viewAlert.x?alertId=36500 |
DISCLOSURE TIMELINE |
|
CREDIT | Оксана |