First published: Tue Mar 21 2017(Updated: )
The decode_residual function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =9.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7208 has a severity rating of medium due to the potential for denial of service and information disclosure.
To fix CVE-2017-7208, upgrade to a patched version of Libav that addresses this vulnerability.
CVE-2017-7208 can be exploited via crafted h264 video files to cause a buffer over-read or leak sensitive information.
CVE-2017-7208 specifically affects Libav version 9.21.
The main function involved in CVE-2017-7208 is the decode_residual function in libavcodec.