cvrf2cusa/cusa/f/flac/flac-1.3.3-6_openEuler-SA-2022-1697.json
Jia Chao fd42fc96e3 release v0.1.2
Signed-off-by: Jia Chao <jiac13@chinaunicom.cn>
2024-08-01 10:25:22 +08:00

14 lines
992 B
JSON

{
"id": "openEuler-SA-2022-1697",
"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2022-1697",
"title": "An update for flac is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP3 and openEuler-22.03-LTS",
"severity": "Medium",
"description": "FLAC stands for Free Lossless Audio Codec, an audio format similar to MP3, but lossless, meaning that audio is compressed in FLAC without any loss in quality.\r\n\r\nSecurity Fix(es):\r\n\r\nIn FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070(CVE-2020-0499)",
"cves": [
{
"id": "CVE-2020-0499",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-0499",
"severity": "Medium"
}
]
}