In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-11-09T11:00:00

Updated: 2024-08-05T11:30:04.258Z

Reserved: 2018-11-09T00:00:00

Link: CVE-2018-19128

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-09T11:29:03.737

Modified: 2019-12-05T21:15:11.833

Link: CVE-2018-19128

cve-icon Redhat

No data.