Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6548

Опубликовано: 02 фев. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in vp9parser::Vp9HeaderParser::SetFrame. Its frame_ could be freed while the corresponding pointer would not be updated, leading to a dangling pointer. This is related to the function OutputCluster in webm_info.cc.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:webmproject:libwebm:*:*:*:*:*:*:*:*
Версия до 1.0.0.27 (включая)

EPSS

Процентиль: 67%
0.00528
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in vp9parser::Vp9HeaderParser::SetFrame. Its frame_ could be freed while the corresponding pointer would not be updated, leading to a dangling pointer. This is related to the function OutputCluster in webm_info.cc.

CVSS3: 9.8
debian
около 8 лет назад

A use-after-free issue was discovered in libwebm through 2018-02-02. I ...

CVSS3: 9.8
github
больше 3 лет назад

A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in vp9parser::Vp9HeaderParser::SetFrame. Its frame_ could be freed while the corresponding pointer would not be updated, leading to a dangling pointer. This is related to the function OutputCluster in webm_info.cc.

EPSS

Процентиль: 67%
0.00528
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-416