CVE-2017-12781: Null Pointer Dereference
The EBMLBufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12781?
CVE-2017-12781 has a severity rating that indicates a denial of service risk due to a null pointer dereference.
How do I fix CVE-2017-12781?
To fix CVE-2017-12781, it is recommended to upgrade to a version of libebml that was released after August 26, 2012.
What systems are affected by CVE-2017-12781?
CVE-2017-12781 affects libebml2 versions through August 26, 2012, and specific versions of mkclean and mkvalidator.
What type of attack does CVE-2017-12781 facilitate?
CVE-2017-12781 facilitates denial of service attacks by allowing attackers to crash an application using crafted mkv files.
How can CVE-2017-12781 be exploited?
CVE-2017-12781 can be exploited by sending a specially crafted mkv file to a vulnerable application to trigger a null pointer dereference.