PT-2021-16575 · Unknown · Libsdffextractor
Published
2021-06-11
·
Updated
2022-10-25
·
CVE-2021-25384
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
libsdffextractor library versions prior to SMR MAY-2021 Release 1
Description:
The issue is related to an improper input validation vulnerability in the
sdfffd parse chunk PROP() function, specifically with the Sample Rate Chunk. This could potentially allow attackers to execute arbitrary code on the mediaextractor process.Recommendations:
For versions prior to SMR MAY-2021 Release 1, update to SMR MAY-2021 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
sdfffd parse chunk PROP() function until a patch is available.Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libsdffextractor