CVE-2018-20001: Input Validation
Published Dec 10, 2018
·Updated
In Libav 12.3, there is a floating point exception in the rangedecodeculshift function (called from rangedecodebits) in libavcodec/apedec.c that will lead to remote denial of service via crafted input.
Affected Software
1 affected component
Libav Libav=12.3
Event History
Dec 10, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20001?
CVE-2018-20001 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-20001?
To fix CVE-2018-20001, upgrade to a version of Libav later than 12.3.
3
What causes CVE-2018-20001?
CVE-2018-20001 is caused by a floating point exception in the range_decode_culshift function.
4
Which versions of Libav are affected by CVE-2018-20001?
Libav version 12.3 is affected by CVE-2018-20001.
5
Can CVE-2018-20001 be exploited by attackers?
Yes, CVE-2018-20001 can be exploited by attackers using crafted input to trigger a remote denial of service.