An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade faad2 | Aug 22, 2024 | Nov 23, 2018 |
| Debian | — | Upgrade faad2 | Aug 30, 2019 | Nov 23, 2018 |
| Gentoo Linux | — | Upgrade media-libs/faad2. | Jun 16, 2020 | Nov 23, 2018 |
| Ubuntu | — | Upgrade faad2 (Ubuntu Pro) | Nov 19, 2024 | Nov 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub