CVE-2018-20360

Name
CVE-2018-20360
Description
An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/knik0/faad2/issues/32
MLIST https://lists.debian.org/debian-lts-announce/2019/08/msg00033.html
GENTOO https://security.gentoo.org/glsa/202006-17
MLIST https://lists.debian.org/debian-lts-announce/2021/10/msg00020.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:audiocoding:freeware_advanced_audio_decoder_2:2.8.8:*:*:*:*:*:*:* freeware_advanced_audio_decoder_2 == None == 2.8.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
faad2 3.10-main 2.9.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed