CVE-2017-18242: Medium severity libavutil vulnerability
Published Mar 22, 2018
·Updated
The applydependentcoupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file.
Affected Software
1 affected component
Libav Libav=12.2
Event History
Mar 22, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18242?
CVE-2017-18242 has a severity classification that reflects a denial of service vulnerability due to an out-of-bounds read.
2
How do I fix CVE-2017-18242?
To fix CVE-2017-18242, update Libav to version 12.3 or later.
3
What does CVE-2017-18242 affect?
CVE-2017-18242 affects Libav version 12.2 specifically in the apply_dependent_coupling function.
4
What type of vulnerability is CVE-2017-18242?
CVE-2017-18242 is a denial of service vulnerability that can be exploited through specially crafted AAC files.
5
Can CVE-2017-18242 be exploited remotely?
Yes, CVE-2017-18242 can be exploited remotely by attackers using crafted AAC files.