PT-2021-6535 · Gpac · Gpac

5N1P3R001

·

Published

2021-09-13

·

Updated

2023-05-27

·

CVE-2021-33361

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GPAC version 1.0.1
Description The issue is related to a memory leak in the afra box read function in MP4Box, a component of the GPAC multimedia platform. This allows attackers to read memory via a crafted file, potentially giving them access to confidential data. The exploitation of this issue can be done remotely.
Recommendations For GPAC version 1.0.1, consider disabling the afra box read function until a patch is available to prevent potential memory leaks and unauthorized access to data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2022-01795
CVE-2021-33361
DSA-5411-1

Affected Products

Gpac