First published: Thu Mar 22 2018(Updated: )
The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18242 has a severity classification that reflects a denial of service vulnerability due to an out-of-bounds read.
To fix CVE-2017-18242, update Libav to version 12.3 or later.
CVE-2017-18242 affects Libav version 12.2 specifically in the apply_dependent_coupling function.
CVE-2017-18242 is a denial of service vulnerability that can be exploited through specially crafted AAC files.
Yes, CVE-2017-18242 can be exploited remotely by attackers using crafted AAC files.