CVE-2021-0561

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
googleandroid
11.0
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
flac
bookworm
1.4.2+ds-2
fixed
bullseye
1.3.3-2+deb11u2
fixed
bullseye (security)
1.3.3-2+deb11u2
fixed
sid
1.4.3+ds-2.1
fixed
trixie
1.4.3+ds-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flac
bionic
Fixed 1.3.2-1ubuntu0.1
released
focal
Fixed 1.3.3-1ubuntu0.1
released
impish
ignored
jammy
Fixed 1.3.3-2ubuntu0.1
released
kinetic
not-affected
trusty
Fixed 1.3.0-2ubuntu0.14.04.1+esm1
released
xenial
Fixed 1.3.1-4ubuntu0.1~esm1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
flac-devel
suse enterprise desktop 15 SP3
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP4
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP5
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP6
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP7
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP3
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP4
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP5
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP6
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP7
1.3.2-3.9.1
fixed
suse enterprise server 15 SP3
1.3.2-3.9.1
fixed
suse enterprise server 15 SP4
1.3.2-3.9.1
fixed
suse enterprise server 15 SP5
1.3.2-3.9.1
fixed
suse enterprise server 15 SP6
1.3.2-3.9.1
fixed
suse enterprise server 15 SP7
1.3.2-3.9.1
fixed
libFLAC++6
suse enterprise desktop 15 SP3
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP4
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP5
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP6
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP7
1.3.2-3.9.1
fixed
suse enterprise sap 12 SP5
1.3.0-18.5.1
fixed
suse enterprise sap 15 SP3
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP4
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP5
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP6
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP7
1.3.2-3.9.1
fixed
suse enterprise server 12 SP3
1.3.0-12.6.1
fixed
suse enterprise server 12 SP5
1.3.0-18.5.1
fixed
suse enterprise server 15 SP3
1.3.2-3.9.1
fixed
suse enterprise server 15 SP4
1.3.2-3.9.1
fixed
suse enterprise server 15 SP5
1.3.2-3.9.1
fixed
suse enterprise server 15 SP6
1.3.2-3.9.1
fixed
suse enterprise server 15 SP7
1.3.2-3.9.1
fixed
libFLAC8
suse enterprise desktop 15 SP3
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP4
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP5
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP6
1.3.2-3.9.1
fixed
suse enterprise desktop 15 SP7
1.3.2-3.9.1
fixed
suse enterprise sap 12 SP5
1.3.0-18.5.1
fixed
suse enterprise sap 15 SP3
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP4
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP5
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP6
1.3.2-3.9.1
fixed
suse enterprise sap 15 SP7
1.3.2-3.9.1
fixed
suse enterprise server 12 SP3
1.3.0-12.6.1
fixed
suse enterprise server 12 SP5
1.3.0-18.5.1
fixed
suse enterprise server 15 SP3
1.3.2-3.9.1
fixed
suse enterprise server 15 SP4
1.3.2-3.9.1
fixed
suse enterprise server 15 SP5
1.3.2-3.9.1
fixed
suse enterprise server 15 SP6
1.3.2-3.9.1
fixed
suse enterprise server 15 SP7
1.3.2-3.9.1
fixed
libFLAC8-32bit
suse enterprise sap 12 SP5
1.3.0-18.5.1
fixed
suse enterprise server 12 SP3
1.3.0-12.6.1
fixed
suse enterprise server 12 SP5
1.3.0-18.5.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
flac
RHEL 9
0:1.3.3-10.el9
fixed
flac-devel
RHEL 9
0:1.3.3-10.el9
fixed
flac-libs
RHEL 9
0:1.3.3-10.el9
fixed