Loading
Generated remediation guidance and an executive summary. No account required.
The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read and later out-of-bounds write), or possibly have unspecified other impact.
Use CWE-125, Webmproject vendor hub and Libwebm product page to widen CVE-2018-6406 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-6548, CVE-2019-9746 and CVE-2018-19212 for nearby disclosures in the same product family.