5.5
CVSSv3

CVE-2017-9256

Published: 27/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote malicious users to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio decoder 2 2.7

Vendor Advisories

Debian Bug report logs - #867724 Multiple security issues Package: src:faad2; Maintainer for src:faad2 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 8 Jul 2017 22:09:01 UTC Severity: important Tags: fixed-upstream, patch, security, ...
the mp4ff_read_stco function in common/mp4ff/mp4atomc in Freeware Advanced Audio Decoder 2 (FAAD2) 27 can cause a denial of service(large loop and CPU consumption) via a crafted mp4 file ...