CVE-2017-17127: Null Pointer Dereference
Published Dec 4, 2017
·Updated
The vc1decodeframe function in libavcodec/vc1dec.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Affected Software
1 affected component
Libav Libav=12.2
Event History
Dec 4, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17127?
CVE-2017-17127 has a severity classification that indicates it can lead to denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2017-17127?
To fix CVE-2017-17127, you should upgrade to a patched version of Libav that resolves the vulnerability.
3
What type of vulnerability is CVE-2017-17127?
CVE-2017-17127 is a denial of service vulnerability present in the vc1_decode_frame function of Libav.
4
Who is affected by CVE-2017-17127?
Users of Libav version 12.2 are affected by CVE-2017-17127.
5
Can CVE-2017-17127 be exploited remotely?
Yes, CVE-2017-17127 can be exploited remotely through crafted files that trigger the vulnerability.