Vulnerabilities > CVE-2018-20196 - Out-of-bounds Write vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 2 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DLA-1899.NASL |
description | Multiple vulnerabilities have been discovered in faad2, the Freeware Advanced Audio Coder : CVE-2018-19502 Heap buffer overflow in the function excluded_channels (libfaad/syntax.c). This vulnerability might allow remote attackers to cause denial of service via crafted MPEG AAC data. CVE-2018-20196 Stack buffer overflow in the function calculate_gain (libfaad/br_hfadj.c). This vulnerability might allow remote attackers to cause denial of service or any unspecified impact via crafted MPEG AAC data. CVE-2018-20199 CVE-2018-20360 NULL pointer dereference in the function ifilter_bank (libfaad/filtbank.c). This vulnerability might allow remote attackers to cause denial of service via crafted MPEG AAC data. CVE-2019-6956 Global buffer overflow in the function ps_mix_phase (libfaad/ps_dec.c). This vulnerability might allow remote attackers to cause denial of service or any other unspecified impact via crafted MPEG AAC data. CVE-2019-15296 Buffer overflow in the function faad_resetbits (libfaad/bits.c). This vulnerability might allow remote attackers to cause denial of service via crafted MPEG AAC data. For Debian 8 |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 128305 |
published | 2019-08-29 |
reporter | This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/128305 |
title | Debian DLA-1899-1 : faad2 security update |
code |
|
References
- https://github.com/knik0/faad2/issues/19
- https://github.com/knik0/faad2/issues/19
- https://lists.debian.org/debian-lts-announce/2019/08/msg00033.html
- https://lists.debian.org/debian-lts-announce/2019/08/msg00033.html
- https://security.gentoo.org/glsa/202006-17
- https://security.gentoo.org/glsa/202006-17
- https://www.debian.org/security/2022/dsa-5109
- https://www.debian.org/security/2022/dsa-5109