{"schema_version":"1.9.0","id":"PUB-A-174302683","published":"2021-06-01T00:00:00Z","modified":"2026-09-10T15:43:18.983809180Z","aliases":["A-174302683","CVE-2021-0561"],"details":"In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","affected":[{"package":{"name":"platform/external/flac","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-06-01"}]}],"versions":["11"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/external/flac/+/368eb3f5bec249a197c95a95583ff8153aa6a87f"],"severity":"Moderate","spl":"2021-06-01","types":["ID"],"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"69340343083601748657416805148163666540","length":1636},"id":"PUB-A-174302683-4d8ef586","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/platform/external/flac/+/368eb3f5bec249a197c95a95583ff8153aa6a87f","target":{"file":"libFLAC/stream_encoder.c","function":"write_bitbuffer_"}},{"deprecated":false,"digest":{"line_hashes":["308515609129822083404769785577559681842","122343089576385096823581201290995179700","111761874591500673215426373446663132174","110080742025860690318431060099634259432"],"threshold":0.9},"id":"PUB-A-174302683-cef0008b","signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/platform/external/flac/+/368eb3f5bec249a197c95a95583ff8153aa6a87f","target":{"file":"libFLAC/stream_encoder.c"}}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-174302683.json"}}],"references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-06-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/external/flac/+/368eb3f5bec249a197c95a95583ff8153aa6a87f"}]}