faac contains free MPEG-4 audio codecs by AudioCoding.com.
An invalid pointer can be dereferenced in the huffcode function of libfaac/huff2.c, leading to a crash.
An attacker with the ability to provide crafted input to faac could cause a denial of service.
There is no known workaround at this time.
All faac users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/faac-1.30"