MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access. References: http://www.openwall.com/lists/oss-security/2018/07/18/3
Created libmp4v2 tracking bugs for this issue: Affects: epel-all [bug 1603225] Affects: fedora-all [bug 1603224]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.