PT-2018-3073 · Freeware +1 · Faad2 +1
Fantasy7082
·
Published
2018-11-23
·
Updated
2023-04-05
·
CVE-2018-20358
5.5
Medium
Base vector | Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Freeware Advanced Audio Decoder 2 (FAAD2) version 2.8.8
Description:
The issue is related to an invalid memory address dereference in the `lt prediction` function, which can cause a segmentation fault and application crash, leading to denial of service. This is due to a buffer overflow error, allowing an attacker to potentially cause a denial of service.
Recommendations:
For Freeware Advanced Audio Decoder 2 (FAAD2) version 2.8.8, consider disabling the `lt prediction` function as a temporary workaround until a patch is available. Restrict access to the affected `lt predict.c` module to minimize the risk of exploitation.
Exploit
Fix
DoS
Buffer Overflow
Weakness Enumeration
Related Identifiers
Affected Products
References · 110
- 🔥 https://github.com/knik0/faad2/issues/31⭐ 175 🔗 78 · Exploit
- 🔥 https://github.com/TeamSeri0us/pocs/blob/master/faad/global-buffer-overflow%40ps_mix_phase.md⭐ 42 🔗 18 · Exploit
- 🔥 https://github.com/TeamSeri0us/pocs/tree/master/faad⭐ 42 🔗 18 · Exploit
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32276 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9256 · Security Note
- https://cve.org/CVERecord?id=CVE-2018-20358 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9253 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9254 · Security Note
- https://bdu.fstec.ru/vul/2019-03597 · Security Note
- https://bdu.fstec.ru/vul/2019-03605 · Security Note
- https://errata.altlinux.org/ALT-PU-2023-1579 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20358 · Security Note
- https://bdu.fstec.ru/vul/2022-01667 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9221 · Security Note
- https://security-tracker.debian.org/tracker/DSA-4522-1 · Vendor Advisory