6.8
CVSSv2

CVE-2018-20196

Published: 18/12/2018 Updated: 22/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio decoder 2 2.8.8

debian debian linux 8.0

debian debian linux 10.0

Vendor Advisories

Multiple vulnerabilities have been discovered in the freeware Advanced Audio Decoder, which may result in denial of service or potentially the execution of arbitrary code if malformed media files are processed For the oldstable distribution (buster), these problems have been fixed in version 2100-1~deb10u1 We recommend that you upgrade your faa ...
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadjc in Freeware Advanced Audio Decoder 2 (FAAD2) 288 A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled ...