CVE-2017-5984: Medium severity libavutil vulnerability
Published May 22, 2019
·Updated
In libavcodec in Libav 9.21, ffh264executerefpicmarking() has a heap-based buffer over-read.
Affected Software
1 affected component
Libav Libav=9.21
Remediation
Patch Available
Patch Available
Event History
May 22, 2019
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-5984?
CVE-2017-5984 has a medium severity rating due to the risk of potential information disclosure from a heap-based buffer over-read.
2
How do I fix CVE-2017-5984?
To fix CVE-2017-5984, you should update Libav to a version later than 9.21 that addresses this vulnerability.
3
What software is affected by CVE-2017-5984?
CVE-2017-5984 affects Libav version 9.21 specifically.
4
What is a heap-based buffer over-read in relation to CVE-2017-5984?
A heap-based buffer over-read in CVE-2017-5984 occurs when the program attempts to read more data than allocated in the heap memory, potentially leading to information leakage.
5
Is CVE-2017-5984 exploitable in any environment?
CVE-2017-5984 may be exploitable in environments where untrusted input is processed using Libav, thus caution is advised.