CVE-2018-5684

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
14/01/2018
Last modified:
02/02/2018

Description

In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) and program failure with a crafted avi file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libav:libav:*:*:*:*:*:*:*:* 12.2 (including)


References to Advisories, Solutions, and Tools