Related Vulnerabilities: CVE-2019-6956  

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.

Severity High

Remote Yes

Type Arbitrary code execution

Description

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.

AVG-2660 faad2 2.8.8-1 2.9.0-1 High Fixed

https://sourceforge.net/p/faac/bugs/240/
https://github.com/knik0/faad2/issues/39
https://github.com/knik0/faad2/commit/6823e6610c9af1b0080cb22b9da03efb208d7d57