4.4.8From commit messages
n4.4.8
Fixed 10
- HEVC decoder issues including missing-ref fill limiting to coded planes, window parameter validation, and NAL layer ID filtering.
- Dirac decoder heap buffer overflow in edge_emu_buffer and mctmp row coverage.
- Multiple integer overflow and signed overflow vulnerabilities in audio and video codecs including fastaudio, adpcm, on2avc, truespeech, and vc2enc_dwt.
- Buffer overflow and bounds checking issues in various demuxers including matroska, mov, flac, vqf, and nuv.
- JPEG2000 decoder issues including mask computation in decode_clnpass, header variable clearing, and lowres option handling.
- RTP payload validation in rtpenc_aac, rtpenc_xiph, and rtpenc_amr to reject invalid packet sizes.
- Format string and injection vulnerabilities in FTP demuxer for CR/LF in URL path and HTTP for unterminated request-line tokens.
- Scale and filter issues including off-by-one in boxblur, uyvytoyuv422 overwrite on odd width, and subsampled alpha plane overread.
- Memory safety issues in wave metadata chunks, MagicYUV slice validation, drawtext glyph deallocation, and stereotools buffer sizing.
- H.264 and H.265 parsing issues including color_frame chroma-width underflow protection and mmco_reset input length validation.