CVE-2020-18775: Medium severity libavutil vulnerability
Published Aug 23, 2021
·Updated
In Libav 12.3, there is a heap-based buffer over-read in vc1decodebmbintfi in vc1block.c that allows an attacker to cause denial-of-service via a crafted file.
Affected Software
1 affected component
Libav Libav=12.3
Event History
Aug 23, 2021
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18775?
CVE-2020-18775 has been classified as a high-severity vulnerability due to its potential to cause denial-of-service.
2
How do I fix CVE-2020-18775?
To fix CVE-2020-18775, upgrade Libav to version 12.4 or later as it includes patches for this vulnerability.
3
What type of vulnerability is CVE-2020-18775?
CVE-2020-18775 is a heap-based buffer over-read vulnerability in the Libav library.
4
What versions of Libav are affected by CVE-2020-18775?
CVE-2020-18775 specifically affects Libav version 12.3.
5
Can CVE-2020-18775 be exploited remotely?
Yes, CVE-2020-18775 can be exploited remotely through crafted media files leading to denial-of-service.