5.5

CVE-2017-13666

Exploit
An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.5, as used in libbpg and other products. A small height value can cause an integer underflow, which leads to a crash. This is a different vulnerability than CVE-2017-8906.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MulticorewareincX265 Version0.1
MulticorewareincX265 Version0.2
MulticorewareincX265 Version0.3
MulticorewareincX265 Version0.4
MulticorewareincX265 Version0.4.1
MulticorewareincX265 Version0.5
MulticorewareincX265 Version0.6
MulticorewareincX265 Version0.7
MulticorewareincX265 Version0.8
MulticorewareincX265 Version0.9
MulticorewareincX265 Version1
MulticorewareincX265 Version1.1
MulticorewareincX265 Version1.2
MulticorewareincX265 Version1.3
MulticorewareincX265 Version1.4
MulticorewareincX265 Version1.5
MulticorewareincX265 Version1.6
MulticorewareincX265 Version1.7
MulticorewareincX265 Version1.8
MulticorewareincX265 Version1.9
MulticorewareincX265 Version2.0
MulticorewareincX265 Version2.1
MulticorewareincX265 Version2.2
MulticorewareincX265 Version2.3
MulticorewareincX265 Version2.4
MulticorewareincX265 Version2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-191 Integer Underflow (Wrap or Wraparound)

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.