CVE-2021-0561Out-of-bounds Write in Google Android

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateNov 21

Description

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/androidAndroid-11
NVDgoogle/android11.0
debiandebian/flac< flac 1.3.4-1 (bookworm)
Androidplatform/external_flac11:011:2021-06-01
Debianflac_project/flac< 1.3.3-2+deb11u1+3

Also affects: Debian Linux 10.0, 9.0, Fedora 35, 36

Patches

🔴Vulnerability Details

4
OSV
flac vulnerabilities2022-11-21
GHSA
GHSA-crfc-rr25-6wf2: In append_to_verify_fifo_interleaved_ of stream_encoder2022-05-24
OSV
CVE-2021-0561: In append_to_verify_fifo_interleaved_ of stream_encoder2021-06-22
OSV
CVE-2021-0561: In append_to_verify_fifo_interleaved_ of stream_encoder2021-06-01

📋Vendor Advisories

3
Ubuntu
FLAC vulnerabilities2022-11-21
Red Hat
flac: out of bound write in append_to_verify_fifo_interleaved_ of stream_encoder.c2022-02-23
Debian
CVE-2021-0561: flac - In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible o...2021