CVE-2018-5684: Libav

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) and program failure with a crafted avi file.

Affected products

  • Libav Libav: up to and including 12.2

Published 2018-01-14. Last modified 2026-06-17.