CVE-2018-20361
https://notcve.org/view.php?id=CVE-2018-20361
An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Se ha descubierto una desreferencia de dirección de memoria inválida en la función hf_assembly de libfaad/sbr_hfadj.c en Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. Esta vulnerabilidad causa un error de segmentación y el cierre inesperado de la aplicación, lo que da lugar a una denegación de servicio. • https://github.com/knik0/faad2/issues/30 https://seclists.org/bugtraq/2019/Sep/28 https://security.gentoo.org/glsa/202006-17 https://www.debian.org/security/2019/dsa-4522 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-20360
https://notcve.org/view.php?id=CVE-2018-20360
An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Se ha descubierto una desreferencia de dirección de memoria inválida en la función sbr_process_channel de libfaad/sbr_dec.c en Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. Esta vulnerabilidad causa un error de segmentación y el cierre inesperado de la aplicación, lo que da lugar a una denegación de servicio. • https://github.com/knik0/faad2/issues/32 https://lists.debian.org/debian-lts-announce/2019/08/msg00033.html https://lists.debian.org/debian-lts-announce/2021/10/msg00020.html https://security.gentoo.org/glsa/202006-17 https://www.debian.org/security/2022/dsa-5109 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-20358
https://notcve.org/view.php?id=CVE-2018-20358
An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Se ha descubierto una desreferencia de puntero NULL en la función lt_prediction de libfaad/lt_predict.c en Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. Esta vulnerabilidad causa un error de segmentación y el cierre inesperado de la aplicación, lo que da lugar a una denegación de servicio. • https://github.com/knik0/faad2/issues/31 https://seclists.org/bugtraq/2019/Sep/28 https://security.gentoo.org/glsa/202006-17 https://www.debian.org/security/2019/dsa-4522 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-20196
https://notcve.org/view.php?id=CVE-2018-20196
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled. Hay un desbordamiento de búfer basado en pila en la tercera instancia de la función calculate_gain en libfaad/sbr_hfadj.c en Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. Se podría realizar un ataque de denegación de servicio u otro tipo de impacto sin especificar debido a que el array S_M se gestiona de manera incorrecta. • https://github.com/knik0/faad2/issues/19 https://lists.debian.org/debian-lts-announce/2019/08/msg00033.html https://security.gentoo.org/glsa/202006-17 https://www.debian.org/security/2022/dsa-5109 • CWE-787: Out-of-bounds Write •
CVE-2018-20195
https://notcve.org/view.php?id=CVE-2018-20195
A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. Se ha descubierto una desreferencia de puntero NULL en ic_predict de libfaad/ic_predict.c en Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. Esta vulnerabilidad causa un error de segmentación y el cierre inesperado de la aplicación, lo que da lugar a una denegación de servicio. • https://github.com/knik0/faad2/issues/25 https://seclists.org/bugtraq/2019/Sep/28 https://security.gentoo.org/glsa/202006-17 https://www.debian.org/security/2019/dsa-4522 • CWE-476: NULL Pointer Dereference •