PT-2017-12698 · Matroska · Libebml2

Qflb.Wu

·

Published

2017-11-09

·

Updated

2017-11-22

·

CVE-2017-12801

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libebml2 versions prior to 2012-08-26
Description The issue allows remote attackers to cause a denial of service via a crafted mkv file, specifically through the UpdateDataSize function in ebmlmaster.c.
Recommendations For versions prior to 2012-08-26, consider avoiding the use of the UpdateDataSize function in ebmlmaster.c until a patch is available. Restrict access to crafted mkv files to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12801

Affected Products

Libebml2