CVE ID | CVE-2014-8002 |
CVSS SCORE | 9.5, AV:U/AC:L/Au:U/C:P/I:P/A:P |
AFFECTED VENDORS |
Cisco |
AFFECTED PRODUCTS |
OpenH264 |
VULNERABILITY DETAILS |
The specific flaw exists within the decoder logic. By providing malformed H.264 data to the decoder, an attacker can force a dangling pointer to be referenced after it has been freed. This could result in the execution of arbitrary code in the context of the application.
|
ADDITIONAL DETAILS |
Cisco has issued an update to correct this vulnerability. More details can be found at:
http://tools.cisco.com/security/center/viewAlert.x?alertId=36501 |
DISCLOSURE TIMELINE |
|
CREDIT | Оксана |