CVE-2019-9717: High severity libavutil vulnerability
Published Sep 19, 2019
·Updated
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srttoass in libavcodec/srtdec.c has a complex format argument to sscanf.
Affected Software
1 affected component
Libav Libav<=12.3
Event History
Sep 19, 2019
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Libav vulnerability?
The vulnerability ID for this Libav vulnerability is CVE-2019-9717.
2
What is the severity of CVE-2019-9717?
The severity of CVE-2019-9717 is high with a score of 6.5.
3
What is the affected software for CVE-2019-9717?
The affected software for CVE-2019-9717 is Libav version 12.3.
4
How does CVE-2019-9717 affect the CPU?
CVE-2019-9717 allows attackers to hog the CPU by exploiting a denial of service vulnerability in the subtitle decoder.
5
How can I fix CVE-2019-9717?
To fix CVE-2019-9717, it is recommended to update to a version of Libav that is not affected, if available.