CVE-2018-5766: Buffer Overflow
Published Jan 18, 2018
·Updated
In Libav through 12.2, there is an invalid memcpy in the avpacketref function of libavcodec/avpacket.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted avi file.
Affected Software
1 affected component
Libav Libav<=12.2
Event History
Jan 18, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5766?
CVE-2018-5766 is classified with a severity level that could lead to denial of service through a segmentation fault.
2
How do I fix CVE-2018-5766?
To fix CVE-2018-5766, update to a version of Libav that is higher than 12.2.
3
What types of attacks can occur due to CVE-2018-5766?
CVE-2018-5766 allows remote attackers to execute denial of service attacks by using crafted AVI files.
4
Which software is affected by CVE-2018-5766?
CVE-2018-5766 affects Libav versions up to and including 12.2.
5
In which function does CVE-2018-5766 occur?
CVE-2018-5766 occurs in the av_packet_ref function located in libavcodec/avpacket.c.