MPlayer TwinVQ文件处理栈溢出漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

BUGTRAQ ID: 32822 MPlayer是一款基于Linux的媒体播放程序,支持多种媒体格式。 MPlayer的libmpdemux/demux_vqf.c文件中的demux_open_vqf()函数在处理特制的TwinVQ文件时存在栈溢出漏洞。以下是libmpdemux\demux_vqf.c文件中的有漏洞代码段: [...] 24 static demuxer_t* demux_open_vqf(demuxer_t* demuxer) { ... 49 char chunk_id[4]; 50 unsigned chunk_size; 51 [1] hi->size=chunk_size=stream_read_dword(s); /* include itself */ 52 stream_read(s,chunk_id,4); 53 if(*((uint32_t *)&chunk_id[0])==mmioFOURCC('C','O','M','M')) 54 { 55 [2] char buf[chunk_size-8]; 56 unsigned i,subchunk_size; 57 [3] if(stream_read(s,buf,chunk_size-8)!=chunk_size-8) return NULL; ... 86 i+=subchunk_size+4; 87 while(i<chunk_size-8) 88 { 89 unsigned slen,sid; 90 [4] char sdata[chunk_size]; 91 sid=*((uint32_t *)&buf[i]); i+=4; 92 [5] slen=be2me_32(*((uint32_t *)&buf[i])); i+=4; 93 if(sid==mmioFOURCC('D','S','I','Z')) 94 { 95 hi->Dsiz=be2me_32(*((uint32_t *)&buf[i])); 96 continue; /* describes the same info as size of DATA chunk */ 97 } 98 [6]...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息