4.3
CVSSv2

CVE-2018-19890

Published: 06/12/2018 Updated: 28/12/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An invalid memory address dereference exists in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 2 case.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio coder 1.29.9.2

Vendor Advisories

Debian Bug report logs - #915763 faac: CVE-2018-19886 CVE-2018-19887 CVE-2018-19889 CVE-2018-19890 CVE-2018-19891 Package: src:faac; Maintainer for src:faac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Dec 2018 16:27:04 UTC ...