First published: Thu Mar 22 2018(Updated: )
The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file, related to ff_ps_apply.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-18244 is classified as a medium-level vulnerability due to its potential for denial of service.
To fix CVE-2017-18244, you should upgrade to a version of Libav that is later than 12.2 where the vulnerability has been patched.
CVE-2017-18244 can allow remote attackers to exploit the vulnerability to cause an out-of-bounds read, leading to a denial of service.
CVE-2017-18244 specifically affects Libav version 12.2.
There are no specific workarounds for CVE-2017-18244 other than upgrading to a patched version of Libav.