First published: Fri Jun 15 2018(Updated: )
libavcodec in FFmpeg 4.0 may trigger a NULL pointer dereference if the studio profile is incorrectly detected while converting a crafted AVI file to MPEG4, leading to a denial of service, related to idctdsp.c and mpegvideo.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12460 has been classified as a moderate severity vulnerability.
The mitigation for CVE-2018-12460 involves upgrading to a version of FFmpeg later than 4.0.
CVE-2018-12460 is a denial of service vulnerability caused by a NULL pointer dereference.
The vulnerability affects FFmpeg version 4.0.
Exploitation of CVE-2018-12460 can cause the application to crash, resulting in a denial of service.