GHSA-5pmw-9j92-3c4c

Suggest an improvement
Source
https://github.com/advisories/GHSA-5pmw-9j92-3c4c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-5pmw-9j92-3c4c/GHSA-5pmw-9j92-3c4c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5pmw-9j92-3c4c
Published
2025-02-24T18:27:25Z
Modified
2025-02-24T18:27:25Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenH264 Rust API Openh264 Decoding Functions Heap Overflow Vulnerability
Details

OpenH264 recently reported a heap overflow that was fixed in upstream 63db555 and integrated into our 0.6.6 release. For users relying on Cisco's pre-compiled DLL, we also published 0.8.0, which is compatible with their latest fixed DLL version 2.6.0.

In other words: - if you rely on our source feature only, >=0.6.6 should be safe, - if you rely on libloading, you must upgrade to 0.8.0 and use their latest DLL >=2.6.0.

Users handling untrusted video files should update immediately.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-122",
        "CWE-1395"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-02-24T18:27:25Z"
}
References

Affected packages

crates.io / openh264-sys2

Package

Name
openh264-sys2
View open source insights on deps.dev
Purl
pkg:cargo/openh264-sys2

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.0