#VU16634 NULL pointer dereference in Freeware Advanced Audio Decoder - CVE-2018-20198
Published: December 20, 2018
Freeware Advanced Audio Decoder
Krzysztof Nikiel
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to a NULL pointer dereference in ifilter_bank of libfaad/filtbank.c. A local attacker can submit trigger a segmentation fault that causes the affected software to crash, resulting in a DoS condition because adding to windowed output is mishandled in the LONG_START_SEQUENCE case.