PT-2021-22892 · R3D Sdk+1 · R3D Sdk+1

Published

2021-12-22

·

Updated

2022-09-03

·

CVE-2021-40417

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DPDecoder service (affected versions not specified)
Description The issue arises when the DPDecoder service parses a submitted file as a job, using decoding parameters and fields parsed by the R3D SDK to calculate a heap buffer size. An integer overflow in this calculation can lead to an undersized heap buffer allocation. When this buffer is written to, a heap-based buffer overflow occurs, potentially resulting in code execution under the context of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2021-40417

Affected Products

Dpdecoder Service
R3D Sdk