{"id":"RUSTSEC-2025-0008","summary":"Openh264 Decoding Functions Heap Overflow Vulnerability","details":"OpenH264 recently reported a [heap overflow](https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x) that was fixed in upstream [63db555](https://github.com/cisco/openh264/commit/63db555e30986e3a5f07871368dc90ae78c27449) and [integrated into](https://github.com/ralfbiedert/openh264-rs/commit/3a822fff0b4c9a984622ca2b179fe8898ac54b14) our 0.6.6 release. For users relying on Cisco's pre-compiled DLL, we also published 0.8.0, which is compatible with their latest fixed DLL version  2.6.0. \n\nIn other words:\n- if you rely on our `source` feature only, \u003e=0.6.6 should be safe,\n- if you rely on `libloading`, you must upgrade to 0.8.0 _and_ use their latest DLL \u003e=2.6.0. \n\nUsers handling untrusted video files should update immediately.","aliases":["GHSA-5pmw-9j92-3c4c"],"modified":"2026-02-04T03:50:52.492478Z","published":"2025-02-24T12:00:00Z","related":["CVE-2025-27091"],"database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/openh264-sys2"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2025-0008.html"},{"type":"WEB","url":"https://github.com/cisco/openh264/pull/3818/"}],"affected":[{"package":{"name":"openh264-sys2","ecosystem":"crates.io","purl":"pkg:cargo/openh264-sys2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.8.0"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"arch":[],"functions":[],"os":[]}},"database_specific":{"categories":["memory-corruption"],"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0008.json"}}],"schema_version":"1.7.3"}