CVE-2018-7751
published 2018-04-24CVE-2018-7751: The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML…
PriorityP426medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
2.37%
82.0th percentile
The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:3.4.3-1 (bookworm) | ffmpeg 7:3.4.3-1 (bookworm) |
| ffmpeg | ffmpeg | <= 3.4.2 | — |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fxmr-5w2h-wcxc: The svg_probe function in libavformat/img2dec
ghsa_unreviewed·2022-05-13
CVE-2018-7751 [MEDIUM] CWE-835 GHSA-fxmr-5w2h-wcxc: The svg_probe function in libavformat/img2dec
The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.
OSV
CVE-2018-7751: The svg_probe function in libavformat/img2dec
osv·2018-04-24·CVSS 6.5
CVE-2018-7751 [MEDIUM] CVE-2018-7751: The svg_probe function in libavformat/img2dec
The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.
Debian
CVE-2018-7751: ffmpeg - The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows r...
vendor_debian·2018·CVSS 6.5
CVE-2018-7751 [MEDIUM] CVE-2018-7751: ffmpeg - The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows r...
The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.
Scope: local
bookworm: resolved (fixed in 7:3.4.3-1)
bullseye: resolved (fixed in 7:3.4.3-1)
forky: resolved (fixed in 7:3.4.3-1)
sid: resolved (fixed in 7:3.4.3-1)
trixie: resolved (fixed in 7:3.4.3-1)
No detection rules found.
No public exploits indexed.
arXiv
Generalization-Enhanced Code Vulnerability Detection via Multi-Task Instruction Fine-Tuning
arxiv_fulltext·2024-06-06
Generalization-Enhanced Code Vulnerability Detection via Multi-Task Instruction Fine-Tuning
## Abstract
Code Pre-trained Models (CodePTMs) based vulnerability detection have achieved promising results over recent years.
However, these models struggle to generalize as they typically learn superficial mapping from source code to labels instead of understanding the root causes of code vulnerabilities, resulting in poor performance in real-world scenarios beyond the training instances.
To tackle this challenge, we introduce VulLLM, a novel framework that integrates multi-task learning with Large Language Models (LLMs) to effectively mine deep-seated vulnerability features.
Specifically, we construct two auxiliary tasks beyond the vulnerability detection task.
First, we utilize the vulnerability patches to construct a vulnerability localization task.
Second, based on the vulnerabilit
arXiv
Boosting the Capability of Intelligent Vulnerability Detection by Training in a Human-Learning Manner
arxiv_fulltext·2021-12-12
Boosting the Capability of Intelligent Vulnerability Detection by Training in a Human-Learning Manner
Boosting the Capability of Intelligent Vulnerability Detection by Training in a Human-Learning Manner
Shihan Dou26,
Yueming Wu\|Co-first authors*Corresponding author361,
Wenxuan Li2,
Feng Cheng4,
Wei Yang5,
Yang Liu3
2Fudan University,
3Nanyang Technological University
4Huazhong University of Science and Technology,
5University of Texas at Dallas
## Abstract
Due to its powerful automatic feature extraction, deep learning (DL) has been widely used in source code vulnerability detection.
However, although it performs well on artificial datasets, its performance is not satisfactory when detecting real-world vulnerabilities due to the high complexity of real-world samples.
Meanwhile, almost all DL-based methods consider only designing a new model to detect vulnerabilities and ignore the i
http://www.securityfocus.com/bid/103956https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/a6cba062051f345e8ebfdff34aba071ed73d923fhttps://security.gentoo.org/glsa/202003-65http://www.securityfocus.com/bid/103956https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/a6cba062051f345e8ebfdff34aba071ed73d923fhttps://security.gentoo.org/glsa/202003-65
2018-04-24
Published