CVE-2018-18826: Buffer Overflow
Published Oct 30, 2018
·Updated
There exists a heap-based buffer overflow in vc1decodepmbintfi in vc1block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
Affected Software
1 affected component
Libav Libav=12.3
Event History
Oct 30, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18826?
The severity of CVE-2018-18826 is typically categorized as high due to its potential for causing a denial-of-service.
2
How do I fix CVE-2018-18826?
To fix CVE-2018-18826, you should upgrade Libav to version 12.3 or later, where the vulnerability has been addressed.
3
What causes the vulnerability in CVE-2018-18826?
CVE-2018-18826 is caused by a heap-based buffer overflow in the vc1_decode_p_mb_intfi function in vc1_block.c.
4
What types of attacks can CVE-2018-18826 facilitate?
CVE-2018-18826 allows attackers to execute denial-of-service attacks via crafted AAC files.
5
Which software versions are affected by CVE-2018-18826?
Libav version 12.3 is specifically affected by CVE-2018-18826.