lavc_CopyPicture in modules/codec/avcodec/video.c in...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Jul 18, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 28, 2023
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
References