First published: Thu Jan 18 2018(Updated: )
In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted avi file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | <=12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5766 is classified with a severity level that could lead to denial of service through a segmentation fault.
To fix CVE-2018-5766, update to a version of Libav that is higher than 12.2.
CVE-2018-5766 allows remote attackers to execute denial of service attacks by using crafted AVI files.
CVE-2018-5766 affects Libav versions up to and including 12.2.
CVE-2018-5766 occurs in the av_packet_ref function located in libavcodec/avpacket.c.