CVE-2018-19128: Medium severity Libav Libav vulnerability
Published Nov 9, 2018
·Updated
In Libav 12.3, there is a heap-based buffer over-read in decodeframe in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.
Affected Software
1 affected component
Libav Libav=12.3
Event History
Nov 9, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19128?
CVE-2018-19128 has a severity rating that classifies it as a potential denial-of-service vulnerability.
2
How do I fix CVE-2018-19128?
To fix CVE-2018-19128, upgrade Libav to a version that is not vulnerable, ideally to 12.3 or later where applicable.
3
What type of attack does CVE-2018-19128 facilitate?
CVE-2018-19128 facilitates a denial-of-service attack via specially crafted AVI files.
4
Which software versions are affected by CVE-2018-19128?
CVE-2018-19128 primarily affects Libav version 12.3.
5
What component of Libav is impacted by CVE-2018-19128?
CVE-2018-19128 impacts the decode_frame function in libavcodec/lcldec.c.