First published: Tue Jan 30 2018(Updated: )
The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read and later out-of-bounds write), or possibly have unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmproject Libwebm | <=2018-01-30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6406 is a vulnerability in libwebm that allows remote attackers to cause an information leak or a denial of service.
CVE-2018-6406 has a severity score of 8.8 (high).
CVE-2018-6406 can result in a heap-based buffer over-read and later out-of-bound memory corruption, leading to information disclosure or denial of service.
To fix CVE-2018-6406, it is recommended to update to a version of libwebm after January 30, 2018, when the vulnerability was fixed.
You can find more information about CVE-2018-6406 at the following references: [link1] [link2]