Candidate: CVE-2018-5766 PublicDate: 2018-01-18 07:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5766 https://bugzilla.libav.org/show_bug.cgi?id=1112 Description: In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted avi file. Ubuntu-Description: Notes: ebarretto> No fix available as of 2019-03-01 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libav: upstream_libav: needs-triage precise/esm_libav: DNE trusty_libav: ignored (reached end-of-life) trusty/esm_libav: DNE (trusty was needs-triage) xenial_libav: DNE artful_libav: DNE bionic_libav: DNE cosmic_libav: DNE disco_libav: DNE devel_libav: DNE