[ GLSA 202208-16 ] faac: Denial of service

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166017066261.8.10795703527387723200@a9099abfa3b1>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202208-16
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Low
    Title: faac: Denial of service
     Date: August 10, 2022
     Bugs: #762505
       ID: 202208-16

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability in faac could result in denial of service.

Background
==========

faac contains free MPEG-4 audio codecs by AudioCoding.com.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  media-libs/faac            < 1.30                        >= 1.30

Description
===========

An invalid pointer can be dereferenced in the huffcode function of
libfaac/huff2.c, leading to a crash.

Impact
======

An attacker with the ability to provide crafted input to faac could cause a denial of service.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All faac users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=media-libs/faac-1.30"

References
==========

[ 1 ] CVE-2018-19886
      https://nvd.nist.gov/vuln/detail/CVE-2018-19886

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202208-16

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmL0MaYACgkQFMQkOaVy
+9mT7g//drEhUMBewMTzDtzygu8IgRpTI4wbJhIwiCkdZRUVOjvRte0FSvdJ4Gub
YP64vw4HqqAF24B1qs0SjSwS3PtwcGxOM7K5TRCoLnOxW2mue5QnUneDB1XPUYA7
6HAgrVlthoNTgydrT1eTXAzQk19XFeQNI1hXrzbiiz75VIqxCXzfzyYxcMEN3R+L
SBQ53KbWCsoW8ndqSsUkew3pQlDy5lVov4zNWY7v9EAL+tHPX3zztLbf7s3BWTR1
NIjqcYmb/VtlViDZuclwp78Ev2moilNo2ZW9IzCpQ1iJ6vjoopk7ty7SVz4I7g7V
3/2o4Y4iUtIpjix6I0BJzKehOaFGv8FXybQ8Lnp8V+4xzvRwVJPpl5/pp4Wl5fmZ
FTpBciMwchydW0QUYy/t7571M7rubYQJXy5bTPaYsKUMU0SdglMzJaDARE3w6ErR
zRm1BES1B1/NP2yWN54DUI0LpzFPZeCiiPP9uoT1qZ4MfvnOEgsYBT76ssCw4ua4
vKZB/K65BdP6jOIJgDN0CSDwlry/ws5iiHj9YWnrhFy7QaH/hiY6ZudsGTMie4qW
1t6buxKkDj4pBrQeqwrut3Vnsj2SKPU2guAW1mqnSg4v+Jh7zo7fkHytbZVIpSzw
CXCPg+Abdbk+kJ/8ezg7vuzW9W06RVwosbR00jvdfSdDcDN09ug=
=nctn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.