Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-22219

Опубликовано: 22 авг. 2023
Источник: debian
EPSS Низкий

Описание

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flacfixed1.4.1-1package

Примечания

  • https://github.com/xiph/flac/issues/215

  • https://github.com/xiph/flac/pull/419 (1.4.0)

  • Fixed by: https://github.com/xiph/flac/commit/21fe95ee828b0b9b944f6aa0bb02d24fbb981815 (1.4.0)

EPSS

Процентиль: 59%
0.0038
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

CVSS3: 7.8
redhat
около 2 лет назад

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

CVSS3: 7.8
nvd
около 2 лет назад

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

suse-cvrf
почти 2 года назад

Security update for flac

CVSS3: 9.8
github
около 2 лет назад

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

EPSS

Процентиль: 59%
0.0038
Низкий