An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
[
    {
        "id": "CVE-2021-32272-2d26666e",
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "target": {
            "file": "frontend/mp4read.c",
            "function": "stszin"
        },
        "digest": {
            "function_hash": "91462948182982020859128384302487742294",
            "length": 656.0
        },
        "source": "https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24"
    },
    {
        "id": "CVE-2021-32272-e4e306c9",
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "frontend/mp4read.c"
        },
        "digest": {
            "line_hashes": [
                "327116514384300148477453486440650707654",
                "168372093800188031639950445655704535903",
                "338288728775108395541123149893066390502"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24"
    }
]