CVE-2019-11372
Published: 20 April 2019
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
From the Ubuntu Security Team
It was discovered that MediaInfo contained multiple security issues when handling certain multimedia files. If a user were tricked into opening a crafted multimedia file, an attacker could cause MediaInfo to crash, resulting in a denial of service.
Priority
Status
Package | Release | Status |
---|---|---|
libmediainfo Launchpad, Ubuntu, Debian |
bionic |
Released
(17.12-1ubuntu0.1)
|
cosmic |
Released
(18.03.1-1ubuntu0.1)
|
|
disco |
Released
(18.12-1ubuntu0.1)
|
|
eoan |
Not vulnerable
(18.12-2)
|
|
focal |
Not vulnerable
(18.12-2)
|
|
groovy |
Not vulnerable
(18.12-2)
|
|
hirsute |
Not vulnerable
(18.12-2)
|
|
impish |
Not vulnerable
(18.12-2)
|
|
jammy |
Not vulnerable
(18.12-2)
|
|
precise |
Does not exist
|
|
trusty |
Released
(0.7.67-2ubuntu1+esm1)
|
|
upstream |
Needs triage
|
|
xenial |
Released
(0.7.82-1ubuntu0.1~esm1)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |