faac: Denial of service — GLSA 202208-16

A vulnerability in faac could result in denial of service.

Affected packages

media-libs/faac on all architectures
Affected versions < 1.30
Unaffected versions >= 1.30

Background

faac contains free MPEG-4 audio codecs by AudioCoding.com.

Description

An invalid pointer can be dereferenced in the huffcode function of libfaac/huff2.c, leading to a crash.

Impact

An attacker with the ability to provide crafted input to faac could cause a denial of service.

Workaround

There is no known workaround at this time.

Resolution

All faac users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=media-libs/faac-1.30"
 

References

Release date
August 10, 2022

Latest revision
August 10, 2022: 1

Severity
low

Exploitable
remote

Bugzilla entries