CVE-2017-12800: Null Pointer Dereference
The EBMLFindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12800?
CVE-2017-12800 has a severity rating that indicates it can lead to denial of service due to a null pointer dereference.
How do I fix CVE-2017-12800?
To fix CVE-2017-12800, ensure you upgrade to a version of libebml beyond 2012-08-26 or use updated software that mitigates the vulnerability.
Which software is affected by CVE-2017-12800?
CVE-2017-12800 affects libebml2 versions up to and including 2012-08-26, mkclean version 0.8.9, and mkvalidator version 0.5.1.
What type of attack does CVE-2017-12800 enable?
CVE-2017-12800 enables remote attackers to perform denial of service attacks that can cause an application crash.
Is there a known exploit for CVE-2017-12800?
Yes, there are known exploits for CVE-2017-12800 that utilize crafted mkv files to trigger the vulnerability.