PT-2019-4941 · Mediaarea+3 · Mediainfo+3

Pwd

·

Publicado

2019-04-11

·

Atualizado

2021-03-23

·

CVE-2019-11373

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MediaInfo version 18.12
Description The issue is related to an out-of-bounds read in the File Analyze::Get L8 function of the MediaInfoLib library in MediaArea MediaInfo. This can lead to a crash. The vulnerability is associated with reading data beyond the buffer boundaries, which may allow a remote attacker to cause a denial of service.
Recommendations For MediaInfo version 18.12, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the File Analyze::Get L8 function until a patch is available. Restrict access to the MediaInfoLib library to minimize the risk of exploitation.

Exploit

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1730
BDU:2020-01550
CVE-2019-11373
DLA-2603-1
MGASA-2020-0047
OPENSUSE-SU-2019:1629-1
OPENSUSE-SU-2019:1658-1
OPENSUSE-SU-2019:1889-1
OPENSUSE-SU-2019_1629-1
OPENSUSE-SU-2024:10955-1
USN-3988-1
USN-4859-1

Produtos afetados

Alt Linux
Mediainfo
Suse
Ubuntu