CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
EPSS
Percentile
81.5%
In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a
possible out of bounds read due to a heap buffer overflow. This could lead
to remote information disclosure with no additional execution privileges
needed. User interaction is needed for exploitation.Product:
AndroidVersions: Android-11Android ID: A-156076070
android.googlesource.com/platform/external/flac/+/029048f823ced50f63a92e25073427ec3a9bd909%5E%21/#F0
launchpad.net/bugs/cve/CVE-2020-0499
nvd.nist.gov/vuln/detail/CVE-2020-0499
security-tracker.debian.org/tracker/CVE-2020-0499
source.android.com/security/bulletin/pixel/2020-12-01
ubuntu.com/security/notices/USN-5733-1
www.cve.org/CVERecord?id=CVE-2020-0499
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
EPSS
Percentile
81.5%