CVE-2019-14372: Medium severity libavutil vulnerability
Published Jul 28, 2019
·Updated
In Libav 12.3, there is an infinite loop in the function wvreadblockheader() in the file wvdec.c.
Affected Software
2 affected components
Libav Libav=12.3
Debian Debian Linux=8.0
Event History
Jul 28, 2019
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability severity of CVE-2019-14372?
CVE-2019-14372 is classified as a moderate severity vulnerability due to the infinite loop it creates within the application.
2
How can I mitigate CVE-2019-14372?
To mitigate CVE-2019-14372, you should update Libav to version 12.4 or later, where this issue has been addressed.
3
What software versions are affected by CVE-2019-14372?
CVE-2019-14372 affects Libav version 12.3 specifically.
4
What is the nature of the issue in CVE-2019-14372?
CVE-2019-14372 involves an infinite loop in the function wv_read_block_header() located in wvdec.c.
5
Is there any workaround for CVE-2019-14372?
There are no official workarounds for CVE-2019-14372, so the recommended solution is to upgrade to a patched version.