CVE-2018-18827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
30/10/2018
Last modified:
06/12/2018

Description

There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libav:libav:12.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools