Debian Security Advisory

DSA-5109-1 faad2 -- security update

Date Reported:
27 Mar 2022
Affected Packages:
faad2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-20196, CVE-2018-20199, CVE-2018-20360, CVE-2019-6956, CVE-2021-32272, CVE-2021-32273, CVE-2021-32274, CVE-2021-32276, CVE-2021-32277, CVE-2021-32278.
More information:

Multiple vulnerabilities have been discovered in the freeware Advanced Audio Decoder, which may result in denial of service or potentially the execution of arbitrary code if malformed media files are processed.

For the oldstable distribution (buster), these problems have been fixed in version 2.10.0-1~deb10u1.

We recommend that you upgrade your faad2 packages.

For the detailed security status of faad2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/faad2