CVE-2016-7393: Buffer Overflow
Published Feb 15, 2017
·Updated
Stack-based buffer overflow in the aacsync function in aacparser.c in Libav before 11.5 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
Affected Software
1 affected component
Libav Libav<=11.4
Remediation
Patch Available
Event History
Feb 15, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7393?
CVE-2016-7393 has a high severity level due to its potential to cause denial of service.
2
How do I fix CVE-2016-7393?
To fix CVE-2016-7393, update Libav to version 11.5 or later.
3
What causes the vulnerability in CVE-2016-7393?
The vulnerability in CVE-2016-7393 is caused by a stack-based buffer overflow in the aac_sync function.
4
Who is affected by CVE-2016-7393?
CVE-2016-7393 affects versions of Libav prior to 11.5.
5
What type of attack can be performed using CVE-2016-7393?
An attacker can exploit CVE-2016-7393 to perform remote denial of service attacks through crafted files.