Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9xf-h66v-mjmc

Опубликовано: 13 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

EPSS

Процентиль: 4%
0.00142
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-680

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 дня назад

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

CVSS3: 7.8
nvd
4 дня назад

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

CVSS3: 7.8
debian
4 дня назад

MKVToolNix through 101.0 contains a heap buffer overflow in the bundle ...

EPSS

Процентиль: 4%
0.00142
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-680