Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=5 | vendor advisory |