NULL pointer dereference in Freeware Advanced Audio Decoder - CVE-2018-20199
Published: December 20, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to a NULL pointer dereference in ifilter_bank of libfaad/filtbank.c. A local attacker can trigger a segmentation fault that causes the affected software to crash, resulting in a DoS condition because adding to windowed output is mishandled in the ONLY_LONG_SEQUENCE case.
Affected software
Gentoo Linux
Debian Linux
faad2 (Alpine package)
faad2 (Debian package)
How to mitigate CVE-2018-20199
faad2 (Debian package) - update to 2.10.0-1~deb10u1