7.8
CVSSv3

CVE-2018-19502

Published: 23/11/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio decoder 2 2.8.1

Vendor Advisories

Debian Bug report logs - #914641 faad2: CVE-2018-19502 CVE-2018-19503 CVE-2018-19504 CVE-2019-6956 Package: src:faad2; Maintainer for src:faad2 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 25 Nov 2018 20:51:01 UTC Severity: imp ...
Multiple vulnerabilities have been discovered in faad2, the Freeware Advanced Audio Coder These vulnerabilities might allow remote attackers to cause denial-of-service, or potentially execute arbitrary code if crafted MPEG AAC files are processed For the oldstable distribution (stretch), these problems have been fixed in version 280~cvs20161113 ...