CVE-2018-18826

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
30/10/2018
Last modified:
24/08/2020

Description

There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libav:libav:12.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools