VYPR
Medium severity6.5NVD Advisory· Published Mar 22, 2018· Updated Jun 17, 2026

CVE-2017-18242

CVE-2017-18242

Description

The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted aac file.

Affected products

3
  • Libav/Libavinferred2 versions
    =12.2+ 1 more
    • (no CPE)range: =12.2
    • cpe:2.3:a:libav:libav:12.2:*:*:*:*:*:*:*
  • Libav/libavcodecllm-create
    Range: =12.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.