CVE-2020-18778: Medium severity libavutil vulnerability
Published Aug 23, 2021
·Updated
In Libav 12.3, there is a heap-based buffer over-read in vc1decodepmbintfi in vc1block.c that allows an attacker to cause denial-of-service via a crafted file.
Affected Software
1 affected component
Libav Libav=12.3
Event History
Aug 23, 2021
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18778?
CVE-2020-18778 has a severity level categorized as high due to its potential to cause a denial-of-service.
2
How do I fix CVE-2020-18778?
To mitigate CVE-2020-18778, upgrade to a patched version of Libav that addresses this vulnerability.
3
What type of vulnerability is CVE-2020-18778?
CVE-2020-18778 is classified as a heap-based buffer over-read vulnerability.
4
Which software versions are impacted by CVE-2020-18778?
CVE-2020-18778 specifically affects Libav version 12.3.
5
What can an attacker achieve with CVE-2020-18778?
An attacker can exploit CVE-2020-18778 to trigger a denial-of-service condition using a specially crafted file.