Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-0499

Опубликовано: 15 дек. 2020
Источник: debian
EPSS Низкий

Описание

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flacfixed1.3.3-2package
flacfixed1.3.2-3+deb10u1busterpackage

Примечания

  • https://github.com/xiph/flac/commit/2e7931c27eb15e387da440a37f12437e35b22dd4

  • https://android.googlesource.com/platform/external/flac/+/029048f823ced50f63a92e25073427ec3a9bd909%5E%21/#F0

  • https://source.android.com/security/bulletin/pixel/2020-12-01

EPSS

Процентиль: 90%
0.05474
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070

CVSS3: 4.3
redhat
около 5 лет назад

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070

CVSS3: 4.3
nvd
около 5 лет назад

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070

suse-cvrf
около 5 лет назад

Security update for flac

github
больше 3 лет назад

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070

EPSS

Процентиль: 90%
0.05474
Низкий