The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file. NOTE: this issue exists due to an incomplete fix for CVE-2016-8675.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libav | Libav | * | 11.8 (including) |
Libav | Ubuntu | esm-infra-legacy/trusty | * |
Libav | Ubuntu | precise | * |
Libav | Ubuntu | trusty | * |
Libav | Ubuntu | trusty/esm | * |