Lucene search

K
ubuntucveUbuntu.comUB:CVE-2018-14395
HistoryJul 19, 2018 - 12:00 a.m.

CVE-2018-14395

2018-07-1900:00:00
ubuntu.com
ubuntu.com
8

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.2%

libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a
denial of service (application crash caused by a divide-by-zero error) with
a user crafted audio file when converting to the MOV audio format.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchffmpeg< 7:3.4.4-0ubuntu0.18.04.1UNKNOWN
ubuntu18.10noarchffmpeg< 7:4.0.2-1ubuntu6UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.2%