CVE-2018-19130: Buffer Overflow
Published Nov 9, 2018
·Updated
DISPUTED In Libav 12.3, there is an invalid memory access in vc1decodeframe in libavcodec/vc1dec.c that allows attackers to cause a denial-of-service via a crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127.
Affected Software
1 affected component
Libav Libav=12.3
Event History
Nov 9, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Disputed
11:29 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Libav vulnerability?
The vulnerability ID for this Libav vulnerability is CVE-2018-19130.
2
What is the severity of CVE-2018-19130?
The severity of CVE-2018-19130 is medium with a severity value of 6.5.
3
Which version of Libav is affected by CVE-2018-19130?
The version 12.3 of Libav is affected by CVE-2018-19130.
4
What is the impact of CVE-2018-19130?
CVE-2018-19130 allows attackers to cause a denial-of-service via a crafted aac file.
5
How can I fix CVE-2018-19130?
To fix CVE-2018-19130, it is recommended to update to a version of Libav that does not contain the vulnerability.