CVE-2017-12779: Null Pointer Dereference
Published Nov 9, 2017
·Updated
The NodeGetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.
Affected Software
1 affected component
Matroska Mkvalidator=0.5.1
Event History
Nov 9, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12779?
CVE-2017-12779 has a medium severity level due to its ability to cause a denial of service.
2
How do I fix CVE-2017-12779?
To fix CVE-2017-12779, you should upgrade to the latest version of mkvalidator that addresses this vulnerability.
3
What type of attack does CVE-2017-12779 enable?
CVE-2017-12779 allows attackers to perform remote denial of service attacks through crafted mkv files.
4
Which version of mkvalidator is affected by CVE-2017-12779?
CVE-2017-12779 affects mkvalidator version 0.5.1.
5
What happens if CVE-2017-12779 is exploited?
Exploiting CVE-2017-12779 can result in a null pointer dereference and crash the application.