There is a heap overflow in AVC header slicing. To reproduce the issue, put the attached files on a server and visit http://127.0.0.1/LoadImage.swf?img=slice.flv.
附件:
[slice.flv](https://bugs.chromium.org/p/project-zero/issues/attachment?aid=261560)
[LoadImage.swf](https://bugs.chromium.org/p/project-zero/issues/attachment?aid=261561)
暂无评论