Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25227
HistoryMay 10, 2020 - 11:21 p.m.

Arbitrary Code Execution

2020-05-1023:21:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.003 Low

EPSS

Percentile

70.1%

faad2 is vulnerable to arbitrary code execution. The vulnerability exists as there is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max > G case.

CPENameOperatorVersion
faad2eq2.7-r7