Bug ID 1093339
Summary VUL-1: CVE-2018-11102: libav: A read access violation in the mov_probe function allows remote attackers to cause a denial of service
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/205827/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee alarrosa@suse.com
Reporter jsegitz@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

Created attachment 770275 [details]
Reproducer

CVE-2018-11102

An issue was discovered in Libav 12.3. A read access violation in the mov_probe
function in libavformat/mov.c allows remote attackers to cause a denial of
service (application crash), as demonstrated by avconv.

avconv -y -i POC

doesn't trigger for me on Factory although version mathces

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11102
https://docs.google.com/document/d/18xCwfxMSJiQ9ruQSVaO8-jlcobDjFiYXWOaw31V37xo/edit
https://bugzilla.libav.org/show_bug.cgi?id=1128


You are receiving this mail because: