CVE-2020-0499
Summary
| CVE | CVE-2020-0499 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-15 16:15:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: mingw-flac-1.3.3-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 33 Update: mingw-flac-1.3.3-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: flac-1.3.3-4.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Pixel Update Bulletin—December 2020 | Android Open Source Project |
MISC |
source.android.com |
Vendor Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: mingw-flac-1.3.3-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: mingw-flac-1.3.3-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar |
|
lists.apache.org |
|
| [SECURITY] Fedora 33 Update: flac-1.3.3-4.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2514-1] flac security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199039 Ubuntu Security Notification for FLAC Vulnerabilities (USN-5733-1)
- 296063 Oracle Solaris 11.4 Support Repository Update (SRU) 45.119.2 Missing (CPUAPR2022)
- 500185 Alpine Linux Security Update for flac
- 503925 Alpine Linux Security Update for flac
- 610324 Google Android March 2021 Security Patch Missing for Huawei EMUI
- 670485 EulerOS Security Update for flac (EulerOS-SA-2021-2243)
- 670511 EulerOS Security Update for flac (EulerOS-SA-2021-2269)
- 670570 EulerOS Security Update for flac (EulerOS-SA-2021-2328)
- 670611 EulerOS Security Update for flac (EulerOS-SA-2021-2369)
- 690145 Free Berkeley Software Distribution (FreeBSD) Security Update for flac (49346de2-b015-11eb-9bdf-f8b156b6dcc8)
- 750454 OpenSUSE Security Update for flac (openSUSE-SU-2020:2350-1)
- 750457 OpenSUSE Security Update for flac (openSUSE-SU-2020:2348-1)