CVE-2021-21839: Buffer Overflow
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21839?
CVE-2021-21839 is rated as critical due to the potential for arbitrary code execution through heap-based buffer overflow.
How do I fix CVE-2021-21839?
To fix CVE-2021-21839, upgrade to GPAC version 0.5.2-426-gc5ad4e4+dfsg5-5, 1.0.1+dfsg1-4+deb11u3, or 2.2.1+dfsg1-3.
What systems are affected by CVE-2021-21839?
CVE-2021-21839 affects GPAC version 1.0.1 and Debian GNU/Linux versions 10.0 and 11.0.
Can CVE-2021-21839 be exploited remotely?
Yes, CVE-2021-21839 can be exploited remotely by sending specially crafted MPEG-4 files.
What are the potential impacts of CVE-2021-21839?
Exploitation of CVE-2021-21839 could lead to arbitrary code execution and compromise system integrity.