5.8
CVSSv2

CVE-2019-6956

Published: 25/01/2019 Updated: 22/04/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

An issue exists in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audiocoding freeware advanced audio decoder 2

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #914641 faad2: CVE-2018-19502 CVE-2018-19503 CVE-2018-19504 CVE-2019-6956 Package: src:faad2; Maintainer for src:faad2 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 25 Nov 2018 20:51:01 UTC Severity: imp ...
Multiple vulnerabilities have been discovered in the freeware Advanced Audio Decoder, which may result in denial of service or potentially the execution of arbitrary code if malformed media files are processed For the oldstable distribution (buster), these problems have been fixed in version 2100-1~deb10u1 We recommend that you upgrade your faa ...
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 288 It is a buffer over-read in ps_mix_phase in libfaad/ps_decc ...