4.3
CVSSv2

CVE-2018-19891

Published: 06/12/2018 Updated: 28/12/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An invalid memory address dereference exists in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 10 case.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio coder 1.29.9.2

Vendor Advisories

Debian Bug report logs - #915763 faac: CVE-2018-19886 CVE-2018-19887 CVE-2018-19889 CVE-2018-19890 CVE-2018-19891 Package: src:faac; Maintainer for src:faac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Dec 2018 16:27:04 UTC ...