An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "debian:debian_linux"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.0"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:a:faad2_project:faad2:*:*:*:*:*:*:*:*"
}"2026-05-18T23:22:38Z"
[
{
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2021-32272-2d26666e",
"signature_version": "v1",
"digest": {
"function_hash": "91462948182982020859128384302487742294",
"length": 656.0
},
"source": "https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24",
"target": {
"file": "frontend/mp4read.c",
"function": "stszin"
}
},
{
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2021-32272-e4e306c9",
"signature_version": "v1",
"digest": {
"line_hashes": [
"327116514384300148477453486440650707654",
"168372093800188031639950445655704535903",
"338288728775108395541123149893066390502"
],
"threshold": 0.9
},
"source": "https://github.com/knik0/faad2/commit/1b71a6ba963d131375f5e489b3b25e36f19f3f24",
"target": {
"file": "frontend/mp4read.c"
}
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32272.json"