Loading
In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) and program failure with a crafted avi file.
Cite this page
CVE-2018-5684. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-5684
Use CWE-119, Libav vendor hub and Libav product page to widen CVE-2018-5684 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-4609, CVE-2019-9719 and CVE-2020-18778 for nearby disclosures in the same product family.