An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:faad2_project:faad2:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.0"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
]
}"2026-04-12T03:26:23Z"
[
{
"digest": {
"length": 656.0,
"function_hash": "91462948182982020859128384302487742294"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2021-32272-2d26666e",
"deprecated": false,
"target": {
"function": "stszin",
"file": "frontend/mp4read.c"
},
"source": "https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327116514384300148477453486440650707654",
"168372093800188031639950445655704535903",
"338288728775108395541123149893066390502"
]
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2021-32272-e4e306c9",
"deprecated": false,
"target": {
"file": "frontend/mp4read.c"
},
"source": "https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32272.json"