Stack-based Buffer Underflow in calculate_gain function in FAAD2 2.8.8

Stack-based Buffer Underflow in calculate_gain function in FAAD2 2.8.8

CVE-2018-20197 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled for the G_max > G case.

Learn more about our Web Application Penetration Testing UK.