CVE Vulnerabilities

CVE-2018-7751

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Apr 24, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ffmpeg * 3.4.2 (including)
Ffmpeg Ubuntu artful *
Ffmpeg Ubuntu bionic *
Ffmpeg Ubuntu upstream *
Gst-libav1.0 Ubuntu artful *
Gst-libav1.0 Ubuntu bionic *
Gst-libav1.0 Ubuntu cosmic *
Gst-libav1.0 Ubuntu disco *
Gst-libav1.0 Ubuntu eoan *
Gst-libav1.0 Ubuntu groovy *
Gst-libav1.0 Ubuntu hirsute *
Gst-libav1.0 Ubuntu impish *
Gst-libav1.0 Ubuntu kinetic *
Gst-libav1.0 Ubuntu lunar *
Gst-libav1.0 Ubuntu mantic *
Gst-libav1.0 Ubuntu trusty *
Gst-libav1.0 Ubuntu xenial *
Libav Ubuntu upstream *
Mplayer Ubuntu artful *
Mythtv Ubuntu artful *
Mythtv Ubuntu bionic *
Mythtv Ubuntu cosmic *
Mythtv Ubuntu disco *
Mythtv Ubuntu eoan *
Mythtv Ubuntu groovy *
Mythtv Ubuntu hirsute *
Mythtv Ubuntu impish *
Mythtv Ubuntu kinetic *
Mythtv Ubuntu lunar *
Mythtv Ubuntu mantic *
Mythtv Ubuntu trusty *
Mythtv Ubuntu xenial *
Oxide-qt Ubuntu artful *
Oxide-qt Ubuntu esm-infra/xenial *
Oxide-qt Ubuntu trusty *
Oxide-qt Ubuntu xenial *
Vice Ubuntu artful *
Vice Ubuntu bionic *
Vice Ubuntu cosmic *
Vice Ubuntu disco *
Vice Ubuntu eoan *
Vice Ubuntu groovy *
Vice Ubuntu hirsute *
Vice Ubuntu impish *
Vice Ubuntu kinetic *
Vice Ubuntu lunar *
Vice Ubuntu mantic *
Vice Ubuntu trusty *
Vice Ubuntu xenial *
Vlc Ubuntu artful *

References