Related Vulnerabilities: CVE-2021-32272  

An issue was discovered in faad2 before version 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause code execution.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

An issue was discovered in faad2 before version 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause code execution.

AVG-2403 faad2 2.9.2-1 2.10.0-1 Medium Fixed

https://github.com/knik0/faad2/issues/57
https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24