CVE-2021-32272: High severity libfaad2 vulnerability
Published Sep 20, 2021
·Updated
An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
Affected Software
7 affected componentsFixes available
debian/faad2
2.10.0-1~deb10u12.10.0-12.10.1-12.11.1-1
ubuntu/faad2<2.8.8-1ubuntu0.1~
2.8.8-1ubuntu0.1~
ubuntu/faad2<2.9.1-1ubuntu0.1
2.9.1-1ubuntu0.1
ubuntu/faad2<2.7-8+
2.7-8+
ubuntu/faad2<2.8.0~
2.8.0~
Faad2 Project Faad2<2.10.0
Debian Debian Linux=10.0
Remediation
Event History
Sep 20, 2021
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-32272.
2
What is the severity of CVE-2021-32272?
The severity of CVE-2021-32272 is high.
3
What is the affected software?
The affected software is faad2 before version 2.10.0.
4
How does CVE-2021-32272 work?
CVE-2021-32272 allows an attacker to cause code execution through a heap buffer overflow in the stszin function.
5
How can I fix CVE-2021-32272?
To fix CVE-2021-32272, update faad2 to version 2.10.0 or later.