CVE-2021-21836: Buffer Overflow
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input using the “ctts” FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21836?
CVE-2021-21836 has a high severity rating due to potential exploitation leading to a heap-based buffer overflow.
How do I fix CVE-2021-21836?
You can fix CVE-2021-21836 by upgrading to GPAC version 0.5.2-426-gc5ad4e4+dfsg5-5 or later.
Which versions of GPAC are affected by CVE-2021-21836?
CVE-2021-21836 affects GPAC version 1.0.1 and earlier.
Can CVE-2021-21836 be exploited remotely?
Yes, CVE-2021-21836 can be exploited remotely through specially crafted MPEG-4 files.
What libraries are impacted by CVE-2021-21836?
CVE-2021-21836 impacts the GPAC Project on Advanced Content library specifically in its MPEG-4 decoding functionality.