CVE-2023-38857: Buffer Overflow
Published Aug 15, 2023
·Updated
Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the stcoin function in mp4read.c.
Affected Software
6 affected componentsFixes available
debian/faad2<=2.10.0-1~deb10u1, <=2.10.0-1, <=2.10.1-1
2.11.1-1
ubuntu/faad2<2.8.8-1ubuntu0.1~
2.8.8-1ubuntu0.1~
ubuntu/faad2<2.9.1-1ubuntu0.1
2.9.1-1ubuntu0.1
ubuntu/faad2<2.7-8+
2.7-8+
ubuntu/faad2<2.8.0~
2.8.0~
Faad2 Project Faad2=2.10.1
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 20, 2024
Data Sourced
via Launchpad·12:25 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38857?
CVE-2023-38857 is a buffer overflow vulnerability in the faad2 library, specifically in version 2.10.1.
2
How does CVE-2023-38857 allow an attacker to execute arbitrary code?
CVE-2023-38857 allows a remote attacker to execute arbitrary code by exploiting the buffer overflow vulnerability in the stcoin function in mp4read.c.
3
What is the severity of CVE-2023-38857?
The severity of CVE-2023-38857 is medium, with a score of 5.5.
4
Which software versions are affected by CVE-2023-38857?
Versions 2.10.1 of faad2 library are affected by CVE-2023-38857.
5
How can I fix CVE-2023-38857?
To fix CVE-2023-38857, you should update faad2 library to a version that has a fix for this vulnerability.