Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-21417
HistoryApr 29, 2021 - 12:00 a.m.

CVE-2021-21417

2021-04-2900:00:00
ubuntu.com
ubuntu.com
16
fluidsynth
software synthesizer
soundfont
use after free
violation
invalid
file
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

7.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

39.3%

fluidsynth is a software synthesizer based on the SoundFont 2
specifications. A use after free violation was discovered in fluidsynth,
that can be triggered when loading an invalid SoundFont file.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

7.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

39.3%