Heap-based buffer overflow in Freeware Advanced Audio Decoder - CVE-2021-32277
Published: May 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the sbr_qmf_analysis_32() function in sbr_qmf.c. A remote attacker can trick the victim to open a specially crafted data, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
Debian Linux
Ubuntu
faad (Ubuntu package)
libfaad-dev (Ubuntu package)
libfaad2 (Ubuntu package)
faad2 (Debian package)
How to mitigate CVE-2021-32277
faad (Ubuntu package) - addressed in versions Ubuntu Pro, 2.9.1-1ubuntu0.1
libfaad-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.9.1-1ubuntu0.1
libfaad2 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.9.1-1ubuntu0.1
faad2 (Debian package) - update to 2.10.0-1~deb10u1