#VU16633 NULL pointer dereference in Freeware Advanced Audio Decoder - CVE-2018-20195
Published: December 20, 2018
Freeware Advanced Audio Decoder
Krzysztof Nikiel
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to a NULL pointer dereference in ic_predict of libfaad/ic_predict.c. A local attacker can submit malicious input and trigger a segmentation fault that causes the affected software to crash, resulting in a DoS condition.