CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
10.1%
libstb.so is vulnerable to Denial Of Service. The vulnerability is due to the start_decoder function’s processing of a specially crafted file, leading to a memory allocation failure due to the function returning early, setting f->comment_list to NULL, but f->comment_list_length is not reset. An attacker can exploit this issue to cause a denial of service.