CVE-2023-38858: Buffer Overflow
Published Aug 15, 2023
·Updated
Buffer Overflow vulnerability infaad2 v.2.10.1 allows a remote attacker to execute arbitrary code and cause a denial of service via the mp4info function in mp4read.c:1039.
Affected Software
6 affected componentsFixes available
debian/faad2<=2.10.0-1~deb10u1, <=2.10.0-1, <=2.10.1-1
2.11.1-1
ubuntu/faad2<2.8.8-1ubuntu0.1~
2.8.8-1ubuntu0.1~
ubuntu/faad2<2.9.1-1ubuntu0.1
2.9.1-1ubuntu0.1
ubuntu/faad2<2.7-8+
2.7-8+
ubuntu/faad2<2.8.0~
2.8.0~
Faad2 Project Faad2=2.10.1
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 20, 2024
Data Sourced
via Launchpad·12:25 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38858?
CVE-2023-38858 is a Buffer Overflow vulnerability infaad2 v.2.10.1 that allows a remote attacker to execute arbitrary code and cause a denial of service.
2
How does CVE-2023-38858 affect faad2?
CVE-2023-38858 affects faad2 version 2.10.1.
3
What is the severity of CVE-2023-38858?
CVE-2023-38858 has a severity rating of 6.5 out of 10, which is classified as medium.
4
How can I fix CVE-2023-38858?
To fix CVE-2023-38858, it is recommended to update to a patched version of faad2.
5
Where can I find more information about CVE-2023-38858?
You can find more information about CVE-2023-38858 at the following references: [link1], [link2], [link3].