CVE-2020-0499 PUBLISHED

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070

EPSS 5.47% · 90.1th percentile

Risk Scores

EPSS Score
5.47%
90.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSflac1.3.0-1, 1.3.0-2, 1.3.0-2ubuntu0.14.04.1
Ubuntu:18.04:LTSflac0, 1.3.2-1
Ubuntu:20.04:LTSflac1.3.3-1build1, 0, 1.3.3-1
Ubuntu:Pro:16.04:LTSflac1.3.1-4, 0

Timeline

References

Open in Interactive Console →