CVE-2021-0561

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
google_androidCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
googleandroid
11.0
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
flac
bullseye (security)
1.3.3-2+deb11u2
fixed
bullseye
1.3.3-2+deb11u2
fixed
bookworm
1.4.2+ds-2
fixed
sid
1.4.3+ds-2.1
fixed
trixie
1.4.3+ds-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flac
kinetic
not-affected
jammy
Fixed 1.3.3-2ubuntu0.1
released
impish
ignored
focal
Fixed 1.3.3-1ubuntu0.1
released
bionic
Fixed 1.3.2-1ubuntu0.1
released
xenial
Fixed 1.3.1-4ubuntu0.1~esm1
released
trusty
Fixed 1.3.0-2ubuntu0.14.04.1+esm1
released