Exploit maturity not defined.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about NULL Pointer Dereference vulnerabilities in an interactive lesson.
Start learningA fix was pushed into the master
branch but not yet published.
FFmpeg is a FFmpeg static library ruby binding that is compiled for iOS and CocoaPods.
Affected versions of this package are vulnerable to NULL Pointer Dereference due to an integer underflow in the tts_count
variable. When sc->tts_count
is 0, decrementing it causes it to wrap around to UINT_MAX
, leading to an out-of-bounds access.
git clone https://github.com/FFmpeg/FFmpeg.git
cd FFmpeg
./configure --cc=clang --cxx=clang++ --toolchain=clang-asan --extra-cflags="-I$HOME/ffmpeg_build/include -O0 -fno-omit-frame-pointer -g" --extra-cxxflags="-O0 -fno-omit-frame-pointer -g" --extra-ldflags="-L$HOME/ffmpeg_build/include -fsanitize=address -fsanitize=undefined -lubsan" --disable-optimizations --disable-stripping --enable-cross-compile
make -j30
./ffmpeg -y -i poc tmp.mp4