CVE Vulnerabilities

CVE-2017-13666

Integer Underflow (Wrap or Wraparound)

Published: Aug 24, 2017 | Modified: Sep 07, 2017
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.5, as used in libbpg and other products. A small height value can cause an integer underflow, which leads to a crash. This is a different vulnerability than CVE-2017-8906.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
X265 Multicorewareinc 2.4 2.4
X265 Multicorewareinc 2.2 2.2
X265 Multicorewareinc 2.3 2.3
X265 Multicorewareinc 0.8 0.8
X265 Multicorewareinc 1.1 1.1
X265 Multicorewareinc 0.4.1 0.4.1
X265 Multicorewareinc 2.1 2.1
X265 Multicorewareinc 2.5 2.5
X265 Multicorewareinc 1.9 1.9
X265 Multicorewareinc 1.4 1.4
X265 Multicorewareinc 0.2 0.2
X265 Multicorewareinc 1.7 1.7
X265 Multicorewareinc 0.3 0.3
X265 Multicorewareinc 1.2 1.2
X265 Multicorewareinc 1.8 1.8
X265 Multicorewareinc 0.4 0.4
X265 Multicorewareinc 1.6 1.6
X265 Multicorewareinc 0.5 0.5
X265 Multicorewareinc 0.7 0.7
X265 Multicorewareinc 0.1 0.1
X265 Multicorewareinc 1.5 1.5
X265 Multicorewareinc 0.6 0.6
X265 Multicorewareinc 1 1
X265 Multicorewareinc 2.0 2.0
X265 Multicorewareinc 1.3 1.3
X265 Multicorewareinc 0.9 0.9

References