An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade faad2 | Nov 27, 2019 | Jan 25, 2019 |
| Debian | — | Upgrade faad2 | Aug 30, 2019 | Jan 25, 2019 |
| Gentoo Linux | — | Upgrade media-libs/faad2. | Jun 16, 2020 | Jan 25, 2019 |
| Ubuntu | — | Upgrade faad2 (Ubuntu Pro) | Nov 19, 2024 | Jan 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub