CVE-2018-20359 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Freeware Advanced Audio Decoder 2
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 44.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 22
Latest updateMay 13
Description
An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-4rgj-mg7w-vqg7: An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec↗2022-05-13
CVEList▶
CVE-2018-20359: An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec↗2018-12-22
OSV▶
CVE-2018-20359: An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec↗2018-12-22
📋Vendor Advisories
1Debian▶
CVE-2018-20359: faad2 - An invalid memory address dereference was discovered in the sbrDecodeSingleFrame...↗2018