CVE-2023-38857
Ubuntu Security Notice USN-6313-1
Severity Score
Exploit Likelihood
Affected Versions
1Public Exploits
1Exploited in Wild
-Decision
Descriptions
Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the stcoin function in mp4read.c.
La vulnerabilidad de desbordamiento del búfer infaad2 v.2.10.1 permite a un atacante remoto ejecutar código arbitrario y provocar una denegación de servicio a través de la función stcoin en mp4read.c.
It was discovered that FAAD2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code. It was discovered that FAAD2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-07-25 CVE Reserved
- 2023-08-15 CVE Published
- 2024-11-26 CVE Updated
- 2024-11-26 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|