PT-2021-6776 · Gpac · Gpac Project On Advanced Content Library
Published
2021-05-26
·
Updated
2022-07-29
·
CVE-2021-21862
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GPAC Project on Advanced Content library version 1.0.1
Description
The issue is related to integer truncation vulnerabilities in the MPEG-4 decoding functionality. A specially crafted MPEG-4 input can cause improper memory allocation, resulting in a heap-based buffer overflow that leads to memory corruption. The implementation of the parser used for the
Xtra FOURCC code is affected. An attacker can exploit this by convincing a user to open a malicious video, potentially allowing access to confidential data, disrupting data integrity, and causing a denial of service.Recommendations
For GPAC Project on Advanced Content library version 1.0.1, consider disabling the
Xtra FOURCC code parser until a patch is available to prevent exploitation. Restrict access to videos from untrusted sources to minimize the risk of triggering this vulnerability.Exploit
Fix
Buffer Overflow
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gpac Project On Advanced Content Library