Lucene search

K
freebsdFreeBSD49346DE2-B015-11EB-9BDF-F8B156B6DCC8
HistorySep 08, 2019 - 12:00 a.m.

FLAC -- out-of-bounds read

2019-09-0800:00:00
vuxml.freebsd.org
16

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

EPSS

0.008

Percentile

81.5%

Oss-Fuzz reports:

There is a possible out of bounds read due to a heap
buffer overflow in FLAC__bitreader_read_rice_signed_block
of bitreader.c.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchflac<Β 1.3.3_1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

EPSS

0.008

Percentile

81.5%