FAAD2 Frontend 'decodeMP4file()' Heap Based Buffer Overflow Vulnerability
BID:31219
Info
FAAD2 Frontend 'decodeMP4file()' Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 31219 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4201 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2008 12:00AM |
| Updated: | Nov 10 2008 04:05PM |
| Credit: | ICST-ERCIS (Engineering Research Center of Info Security, Institute of Computer Science & Technology, Peking University / China). |
| Vulnerable: |
Pardus Linux 2008 0 Pardus Linux 2007 0 Gentoo Linux FAAD2 FAAD2 2.6 |
| Not Vulnerable: | |
Discussion
FAAD2 Frontend 'decodeMP4file()' Heap Based Buffer Overflow Vulnerability
FAAD2 (Freeware Advanced Audio Decoder) is prone to a remote heap-based buffer-overflow vulnerability because the command-line frontend fails to adequately validate input from a buffer returned by the decoder library.
Remote attackers can exploit this issue by enticing victims into opening maliciously crafted files with the application's command-line frontend.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
FAAD2 2.6 is vulnerable; other versions may also be affected.
FAAD2 (Freeware Advanced Audio Decoder) is prone to a remote heap-based buffer-overflow vulnerability because the command-line frontend fails to adequately validate input from a buffer returned by the decoder library.
Remote attackers can exploit this issue by enticing victims into opening maliciously crafted files with the application's command-line frontend.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
FAAD2 2.6 is vulnerable; other versions may also be affected.
Exploit / POC
FAAD2 Frontend 'decodeMP4file()' Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FAAD2 Frontend 'decodeMP4file()' Heap Based Buffer Overflow Vulnerability
Solution:
The vendor has released a patch. Please see the references for more information.
FAAD2 FAAD2 2.6
Solution:
The vendor has released a patch. Please see the references for more information.
FAAD2 FAAD2 2.6
-
FAAD2 main_overflow.diff
http://www.audiocoding.com/patch/main_overflow.diff
References
FAAD2 Frontend 'decodeMP4file()' Heap Based Buffer Overflow Vulnerability
References:
References:
- 2008-09-16 Security patch (FAAD2)
- FAAD2 Homepage (FAAD2)