A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the EIGHT_SHORT_SEQUENCE case.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade faad2 | Aug 22, 2024 | Dec 22, 2018 |
| Debian | — | Upgrade faad2 | May 21, 2019 | Dec 22, 2018 |
| Gentoo Linux | — | Upgrade media-libs/faad2. | Jun 16, 2020 | Dec 22, 2018 |
| Ubuntu | — | Upgrade faad2 (Ubuntu Pro) | Nov 19, 2024 | Dec 22, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub