An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade faad2 | Aug 22, 2024 | Sep 20, 2021 |
| Debian | — | Upgrade faad2 | Mar 29, 2022 | Sep 20, 2021 |
| Ubuntu | — | Upgrade libfaad-devUpgrade libfaad2 (Ubuntu Pro)Upgrade libfaad2Upgrade libfaad-dev (Ubuntu Pro)Upgrade faadUpgrade faad (Ubuntu Pro) | Aug 31, 2023 | Sep 20, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub