CVE-2017-18244: Medium severity libavutil vulnerability
Published Mar 22, 2018
·Updated
The stereoprocessing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file, related to ffpsapply.
Affected Software
1 affected component
Libav Libav=12.2
Event History
Mar 22, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18244?
The severity of CVE-2017-18244 is classified as a medium-level vulnerability due to its potential for denial of service.
2
How do I fix CVE-2017-18244?
To fix CVE-2017-18244, you should upgrade to a version of Libav that is later than 12.2 where the vulnerability has been patched.
3
What is the impact of CVE-2017-18244?
CVE-2017-18244 can allow remote attackers to exploit the vulnerability to cause an out-of-bounds read, leading to a denial of service.
4
Which version of Libav is affected by CVE-2017-18244?
CVE-2017-18244 specifically affects Libav version 12.2.
5
Is there a workaround for CVE-2017-18244?
There are no specific workarounds for CVE-2017-18244 other than upgrading to a patched version of Libav.