Vulnerability CVE-2019-6956: Information
Description
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
Severity: HIGH (7.1) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
faad | sisyphus | 2.10.0-alt1 | 2.11.1-alt1 | ALT-PU-2021-1228-2 | 265897 | Fixed |
faad | p10 | 2.10.1-alt1 | 2.11.1-alt1 | ALT-PU-2023-1579-2 | 317731 | Fixed |
faad | p9 | 2.10.0-alt1 | 2.10.0-alt1 | ALT-PU-2021-1316-2 | 266028 | Fixed |
faad | c10f1 | 2.10.1-alt1 | 2.11.1-alt1 | ALT-PU-2023-1579-2 | 317731 | Fixed |
faad | c9f2 | 2.10.0-alt1 | 2.10.0-alt1 | ALT-PU-2021-1341-2 | 266029 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://sourceforge.net/p/faac/bugs/240/ |
|
https://github.com/TeamSeri0us/pocs/blob/master/faad/global-buffer-overflow%40ps_mix_phase.md |
|
[debian-lts-announce] 20190828 [SECURITY] [DLA 1899-1] faad2 security update |
|
GLSA-202006-17 |
|
[debian-lts-announce] 20211024 [SECURITY] [DLA 2792-1] faad2 security update |
|
DSA-5109 |
|