Posted by Ron E on Sep 08
During construction of a Track_Visual object, corrupted sequence metadata
can leave a std::vector<unsigned> uninitialized. When .empty() is called,
it attempts to dereference a null object.
*Root Cause:*
–
Missing input validation when constructing vectors from parsed boxes.
*Impact:*
–
Application crash (DoS).
–
Not exploitable for code execution.
*Evidence:*
==1174955==ERROR: AddressSanitizer: SEGV in…
– Read More – Full Disclosure



