{"id":"UBUNTU-CVE-2018-19130","details":"** DISPUTED ** In Libav 12.3, there is an invalid memory access in vc1_decode_frame in libavcodec/vc1dec.c that allows attackers to cause a denial-of-service via a crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127.","modified":"2018-11-09T11:29:00Z","published":"2018-11-09T11:29:00Z","withdrawn":"2025-06-23T15:53:15Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-19130"},{"type":"REPORT","url":"https://bugzilla.libav.org/show_bug.cgi?id=1139"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-19130"}],"affected":[{"package":{"name":"libav","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/libav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6:0.8.7-1ubuntu2","6:9.10-1ubuntu1","6:9.10-1ubuntu2","6:9.10-1ubuntu5","6:9.10-1ubuntu6","6:9.10-1ubuntu7","6:9.11-2ubuntu1","6:9.11-2ubuntu2","6:9.13-0ubuntu0.14.04.1","6:9.14-0ubuntu0.14.04.1","6:9.16-0ubuntu0.14.04.1","6:9.18-0ubuntu0.14.04.1","6:9.20-0ubuntu0.14.04.1","6:9.20-0ubuntu0.14.04.1+esm1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-19130.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}