First published: Sun Jul 28 2019(Updated: )
In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =12.3 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14372 is classified as a moderate severity vulnerability due to the infinite loop it creates within the application.
To mitigate CVE-2019-14372, you should update Libav to version 12.4 or later, where this issue has been addressed.
CVE-2019-14372 affects Libav version 12.3 specifically.
CVE-2019-14372 involves an infinite loop in the function wv_read_block_header() located in wvdec.c.
There are no official workarounds for CVE-2019-14372, so the recommended solution is to upgrade to a patched version.