First published: Tue Oct 30 2018(Updated: )
There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18826 is typically categorized as high due to its potential for causing a denial-of-service.
To fix CVE-2018-18826, you should upgrade Libav to version 12.3 or later, where the vulnerability has been addressed.
CVE-2018-18826 is caused by a heap-based buffer overflow in the vc1_decode_p_mb_intfi function in vc1_block.c.
CVE-2018-18826 allows attackers to execute denial-of-service attacks via crafted AAC files.
Libav version 12.3 is specifically affected by CVE-2018-18826.