Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44515
HistoryNov 30, 2023 - 7:08 p.m.

Denial Of Service (DoS)

2023-11-3019:08:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
denial of service
buffer overflow
stcoin function
mp4read.c
malicious code
application crash
faad2 vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

34.9%

faad2 is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the buffer overflow in the stcoin function of mp4read.c, allowing an attacker to inject and execute malicious code and cause application crash

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

34.9%