CVE-2019-15296 is a buffer overflow vulnerability in Freeware Advanced Audio Decoder 2 (FAAD2) version 2.8.8, specifically within the faad_resetbits function in libfaad/bits.c, affecting audiocoding and Debian distributions. This high-severity flaw (CVSS 7.8) could lead to complete compromise of confidentiality, integrity, and availability if a local attacker tricks a user into processing a specially crafted audio file. Despite its potential impact, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.8CPE matchmatch criteria | cpe:2.3:a:audiocoding:freeware_advanced_audio_decoder_2:2.8.8:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.