Name | CVE-2018-7339 |
Description | The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers to cause a denial of service (overflow, insufficient memory allocation, and segmentation fault) or possibly have unspecified other impact via a crafted mp4 file. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 893544 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
mp4v2 | source | (unstable) | (unfixed) | low | 893544 |
[stretch] - mp4v2 <no-dsa> (Minor issue)
[jessie] - mp4v2 <no-dsa> (Minor issue)
[wheezy] - mp4v2 <ignored> (Minor issue)
https://github.com/pingsuewim/libmp4_bof