Vulnerability Name: | CVE-2016-7477 (CCN-125066) | ||||||||||||
Assigned: | 2016-09-09 | ||||||||||||
Published: | 2017-02-15 | ||||||||||||
Updated: | 2017-02-17 | ||||||||||||
Summary: | The ff_put_pixels8_xy2_mmx function in rnd_template.c in Libav 11.7 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted mp3 file. Note: this issue was originally reported as involving a NULL pointer dereference. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
4.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-476 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-7477 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160921 Re: libav: NULL pointer dereference in ff_put_pixels8_xy2_mmx (rnd_template.c) Source: BID Type: Third Party Advisory, VDB Entry 93042 Source: CCN Type: agostino's blog, September 20, 2016 libav: invalid memory access in ff_put_pixels8_xy2_mmx (rnd_template.c) Source: MISC Type: Third Party Advisory, VDB Entry https://blogs.gentoo.org/ago/2016/09/20/libav-null-pointer-dereference-in-ff_put_pixels8_xy2_mmx-rnd_template-c/ Source: XF Type: UNKNOWN libav-cve20167477-dos(125066) Source: CCN Type: Libav Web site Libav | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |