OSV-2024-233

Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openh264/OSV-2024-233.yaml
Published
2024-04-03T00:12:42.632653Z
Modified
2024-04-29T11:29:24.123337Z
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=66003

Crash type: Use-of-uninitialized-value
Crash state:
WelsDec::CWelsDecoder::ReorderPicturesInDisplay
WelsDec::CWelsDecoder::DecodeFrame2WithCtx
WelsDec::CWelsDecoder::DecodeFrame2
References

Affected packages

OSS-Fuzz / openh264

Package

Name
openh264

Affected ranges

Affected versions

v2.*

v2.4.1

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "fixed_range": "c59550a2147c255cc8e09451f6deb96de2526b6d:f86f0e47ef28fdf33b15a64eac8359cc1a88dfe6"
}