Buffer overflow in the CCdecode function in contrib/ntsc-cc.c in the zvbi-ntsc-cc tool in Zapping VBI Library (ZVBI) before 0.2.25 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long data during a reception error. NOTE: some of these details are obtained from third party information. The vendor has addressed this issue through the release of updated version 0.2.25: http://sourceforge.net/projects/zapping/
Publication date: Fri, 08 Jun 2007 02:30:00 +0000