CVE-2017-12783: Input Validation
Published Nov 9, 2017
·Updated
The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
Affected Software
3 affected components
Matroska Libebml2<=2012-08-26
Matroska Mkclean=0.8.9
Matroska Mkvalidator=0.5.1
Event History
Nov 9, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12783?
CVE-2017-12783 has a severity rating that indicates a denial of service vulnerability.
2
What vulnerability does CVE-2017-12783 pertain to?
CVE-2017-12783 pertains to a denial of service vulnerability in the ReadDataFloat function of libebml2.
3
How do I fix CVE-2017-12783?
To fix CVE-2017-12783, upgrade libebml2 and other affected applications to versions released after August 26, 2012.
4
What types of attacks can CVE-2017-12783 be used for?
CVE-2017-12783 can be exploited to cause application crashes via crafted mkv files.
5
Which software is affected by CVE-2017-12783?
CVE-2017-12783 affects libebml2 versions up to 2012-08-26, mkclean version 0.8.9, and mkvalidator version 0.5.1.