PT-2021-16575 · Unknown · Libsdffextractor

Published

2021-06-11

·

Updated

2022-10-25

·

CVE-2021-25384

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: libsdffextractor library versions prior to SMR MAY-2021 Release 1
Description: The issue is related to an improper input validation vulnerability in the sdfffd parse chunk PROP() function, specifically with the Sample Rate Chunk. This could potentially allow attackers to execute arbitrary code on the mediaextractor process.
Recommendations: For versions prior to SMR MAY-2021 Release 1, update to SMR MAY-2021 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the sdfffd parse chunk PROP() function until a patch is available.

Fix

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-25384

Affected Products

Libsdffextractor