First published: Tue Mar 21 2017(Updated: )
The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =9.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7206 has a severity rating that indicates it may lead to denial of service or exposure of sensitive information.
To fix CVE-2017-7206, upgrade to a version of Libav higher than 9.21 that addresses this vulnerability.
CVE-2017-7206 enables a remote attacker to cause a denial of service or access sensitive memory information.
CVE-2017-7206 specifically affects the ff_h2645_extract_rbsp function in libavcodec.
CVE-2017-7206 is exploitable using crafted H264 video files designed to trigger the vulnerability.