CVE-2018-6406: High severity webmproject Libwebm vulnerability
The function ParseVP9SuperFrameIndex in common/libwebmutil.cc in libwebm through 2018-01-30 does not validate the childframelength data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read and later out-of-bounds write), or possibly have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6406?
CVE-2018-6406 is a vulnerability in libwebm that allows remote attackers to cause an information leak or a denial of service.
How severe is CVE-2018-6406?
CVE-2018-6406 has a severity score of 8.8 (high).
What is the impact of CVE-2018-6406?
CVE-2018-6406 can result in a heap-based buffer over-read and later out-of-bound memory corruption, leading to information disclosure or denial of service.
How can I fix CVE-2018-6406?
To fix CVE-2018-6406, it is recommended to update to a version of libwebm after January 30, 2018, when the vulnerability was fixed.
Where can I find more information about CVE-2018-6406?
You can find more information about CVE-2018-6406 at the following references: [link1] [link2]