yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2018-20357
Component Overview
Vulnerability Overview
Name
CVE-2018-20357
Source
NVD (
link
)
Debian (
link
)
Description
A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.
CWEs
CWE-476
Published Date
Dec 22, 2018
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/knik0/faad2/issues/28
Exploit
https://github.com/knik0/faad2/issues/28
Exploit
Analysis
#
Affected Component
Analysis
faad2
Exploitable
Vulnerability Ratings
#
5.5
other
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
faad2
buildroot
2025.02.x
2.11.1
Not Affected
faad2
buildroot
master
2.11.2
Not Affected
faad2
yocto
master
2.11.2+git
Not Affected
faad2
yocto
scarthgap
2.11.1+git
Not Affected