4.3
CVSSv2

CVE-2017-9218

Published: 27/06/2017 Updated: 30/06/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote malicious users to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio decoder 2 2.7

Vendor Advisories

Debian Bug report logs - #867724 Multiple security issues Package: src:faad2; Maintainer for src:faad2 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 8 Jul 2017 22:09:01 UTC Severity: important Tags: fixed-upstream, patch, security, ...
the mp4ff_read_stsd function in common/mp4ff/mp4atomc in Freeware Advanced Audio Decoder 2 (FAAD2) 27 can cause a denial of service(invalid memory read and application crash) via a crafted mp4 file ...