{"id":"CVE-2017-7208","details":"The decode_residual function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.","modified":"2026-07-08T10:54:45.084567Z","published":"2017-03-21T06:59:00.447Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/97005"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-4012"},{"type":"REPORT","url":"https://bugzilla.libav.org/show_bug.cgi?id=1000"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libav/libav","events":[{"introduced":"620810803b36e02cfbbfb1cb737dc25f858858cd"},{"last_affected":"620810803b36e02cfbbfb1cb737dc25f858858cd"}],"database_specific":{"cpe":"cpe:2.3:a:libav:libav:9.21:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.21"},{"last_affected":"9.21"}],"source":"CPE_STRING"}}],"versions":["9.21","v9.21"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7208.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"}]}