vulnerability
Ubuntu: (CVE-2019-6956): faad2 vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:N/AC:M/Au:N/C:P/I:N/A:P) | Jan 25, 2019 | Nov 19, 2024 | Aug 19, 2025 |
Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:P)
Published
Jan 25, 2019
Added
Nov 19, 2024
Modified
Aug 19, 2025
Description
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
Solution
ubuntu-pro-upgrade-faad2
References
- CVE-2019-6956
- https://attackerkb.com/topics/CVE-2019-6956
- CWE-125
- DEBIAN-DSA-5109
- URL-https://github.com/TeamSeri0us/pocs/blob/master/faad/global-buffer-overflow%40ps_mix_phase.md
- URL-https://security-tracker.debian.org/tracker/DLA-1899-1
- URL-https://sourceforge.net/p/faac/bugs/240/
- URL-https://www.cve.org/CVERecord?id=CVE-2019-6956
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.