Buffer overflow - CVE-2018-20360
Published: December 22, 2018 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Affected software
Debian Linux
faad2 (Alpine package)
faad2 (Debian package)
How to mitigate CVE-2018-20360
faad2 (Debian package) - update to 2.10.0-1~deb10u1