CVE-2017-18246: Medium severity libavutil vulnerability
Published Mar 23, 2018
·Updated
The pcmencodeframe function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted media file.
Affected Software
1 affected component
Libav Libav=12.2
Event History
Mar 23, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18246?
CVE-2017-18246 has been classified as a denial of service vulnerability due to a heap-based buffer over-read.
2
How do I fix CVE-2017-18246?
To mitigate CVE-2017-18246, upgrade Libav to version 12.3 or later.
3
What types of attacks can exploit CVE-2017-18246?
An attacker can exploit CVE-2017-18246 by sending a crafted media file that causes a denial of service.
4
Which software versions are affected by CVE-2017-18246?
CVE-2017-18246 affects Libav version 12.2.
5
What function in Libav is vulnerable in CVE-2017-18246?
The vulnerability in CVE-2017-18246 is located in the pcm_encode_frame function in libavcodec/pcm.c.