{"id":"CVE-2018-0429","details":"Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream.","modified":"2026-07-08T12:05:44.070873Z","published":"2018-08-09T20:29:00.143Z","database_specific":{"unresolved_ranges":[{"vendor_product":"cisco:thor_video_codec","cpes":["cpe:2.3:a:cisco:thor_video_codec:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"2018-8-8"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105059"},{"type":"FIX","url":"https://github.com/cisco/thor/commit/18de8f9f0762c3a542b1122589edb8af859d9813"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cisco/thor","events":[{"introduced":"0"},{"fixed":"18de8f9f0762c3a542b1122589edb8af859d9813"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-0429.json","vanir_signatures_modified":"2026-07-08T12:05:44Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/cisco/thor/commit/18de8f9f0762c3a542b1122589edb8af859d9813","target":{"file":"dec/read_bits.c"},"deprecated":false,"digest":{"line_hashes":["264814424545593474819111638168033048335","29380800834262278354043021163604966213","231297882385772315541497452566715376537","54446572204488571998172803927986542782"],"threshold":0.9},"id":"CVE-2018-0429-0751e691"},{"deprecated":false,"digest":{"function_hash":"128582145183835901605865670488554236518","length":1391},"id":"CVE-2018-0429-0835167c","signature_type":"Function","signature_version":"v1","source":"https://github.com/cisco/thor/commit/18de8f9f0762c3a542b1122589edb8af859d9813","target":{"file":"dec/read_bits.c","function":"read_sequence_header"}},{"digest":{"line_hashes":["21326757575281421226059430203205250345","6138405237118955260785957201798221957","313804954981227923332955466962014065255","36170804589396744627477821375121705203"],"threshold":0.9},"id":"CVE-2018-0429-209e3e68","signature_type":"Line","signature_version":"v1","source":"https://github.com/cisco/thor/commit/18de8f9f0762c3a542b1122589edb8af859d9813","target":{"file":"dec/decode_block.c"},"deprecated":false},{"digest":{"function_hash":"96866324258601263171874906808154813146","length":1569},"id":"CVE-2018-0429-935ea3ee","signature_type":"Function","signature_version":"v1","source":"https://github.com/cisco/thor/commit/18de8f9f0762c3a542b1122589edb8af859d9813","target":{"function":"(process_block_dec)","file":"dec/decode_block.c"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}