faac: Denial of service A vulnerability in faac could result in denial of service. faac 2022-08-10 2022-08-10 762505 remote 1.30 1.30

faac contains free MPEG-4 audio codecs by AudioCoding.com.

An invalid pointer can be dereferenced in the huffcode function of libfaac/huff2.c, leading to a crash.

An attacker with the ability to provide crafted input to faac could cause a denial of service.

There is no known workaround at this time.

All faac users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/faac-1.30"
CVE-2018-19886 ajak ajak