CVE-2020-36150Out-of-bounds Read in Libmysofa

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 24

Description

Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated memory block.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/libmysofa< libmysofa 1.2~dfsg0-1 (bookworm)
Debiansymonics/libmysofa< 1.2~dfsg0-1+3
NVDsymonics/libmysofa0.51.1

Also affects: Fedora 32

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9w8f-hpgh-vxjr: Incorrect handling of input data in loudness function in the libmysofa library 02022-05-24
OSV
CVE-2020-36150: Incorrect handling of input data in loudness function in the libmysofa library 02021-02-08

📋Vendor Advisories

1
Debian
CVE-2020-36150: libmysofa - Incorrect handling of input data in loudness function in the libmysofa library 0...2020
CVE-2020-36150 — Out-of-bounds Read in Debian Libmysofa | cvebase