There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max <= G case.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-faad2 | Aug 22, 2024 | Dec 18, 2018 | |
| Debian | debian-upgrade-faad2 | May 21, 2019 | Dec 18, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-media-libs-faad2 | Jun 16, 2020 | Dec 18, 2018 | |
| Ubuntu | ubuntu-pro-upgrade-faad2 | Nov 19, 2024 | Dec 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub