Heap-based buffer overflow in Freeware Advanced Audio Decoder - CVE-2021-32274
Published: May 30, 2022
Freeware Advanced Audio Decoder
Krzysztof Nikiel
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the sbr_qmf_synthesis_64() function in sbr_qmf.c. A remote attacker can trick the victim to open a specially crafted data, trigger a heap-based buffer overflow and execute arbitrary code on the target system.