CVE Vulnerabilities

CVE-2018-18829

NULL Pointer Dereference

Published: Oct 30, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
LibavLibav12.3 (including)12.3 (including)
Gst-libav1.0Ubuntubionic*
Gst-libav1.0Ubuntucosmic*
Gst-libav1.0Ubuntudisco*
Gst-libav1.0Ubuntueoan*
Gst-libav1.0Ubuntufocal*
Gst-libav1.0Ubuntugroovy*
Gst-libav1.0Ubuntuhirsute*
Gst-libav1.0Ubuntuimpish*
Gst-libav1.0Ubuntukinetic*
Gst-libav1.0Ubuntulunar*
Gst-libav1.0Ubuntumantic*
Gst-libav1.0Ubuntuoracular*
Gst-libav1.0Ubuntuplucky*
Gst-libav1.0Ubuntutrusty*
Gst-libav1.0Ubuntuxenial*
LibavUbuntutrusty*
LibavUbuntutrusty/esm*
Qtwebengine-opensource-srcUbuntubionic*
Qtwebengine-opensource-srcUbuntucosmic*
Qtwebengine-opensource-srcUbuntudisco*
Qtwebengine-opensource-srcUbuntueoan*
Qtwebengine-opensource-srcUbuntufocal*
Qtwebengine-opensource-srcUbuntugroovy*
Qtwebengine-opensource-srcUbuntuhirsute*
Qtwebengine-opensource-srcUbuntuimpish*
Qtwebengine-opensource-srcUbuntukinetic*
Qtwebengine-opensource-srcUbuntulunar*
Qtwebengine-opensource-srcUbuntumantic*
Qtwebengine-opensource-srcUbuntuoracular*
Qtwebengine-opensource-srcUbuntuplucky*
VlcUbuntubionic*
VlcUbuntucosmic*
VlcUbuntudisco*
VlcUbuntueoan*
VlcUbuntugroovy*
VlcUbuntuhirsute*
VlcUbuntuimpish*
VlcUbuntukinetic*
VlcUbuntulunar*
VlcUbuntumantic*
VlcUbuntutrusty*
VlcUbuntuxenial*

Potential Mitigations

References