CVE-2021-21852: Buffer Overflow
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21852?
CVE-2021-21852 has been classified as a high severity vulnerability due to its potential for exploitation through crafted MPEG-4 files.
How do I fix CVE-2021-21852?
To remediate CVE-2021-21852, users should upgrade the GPAC Project on Advanced Content library to versions 0.94+ds1-2 or higher.
What types of vulnerabilities are present in CVE-2021-21852?
CVE-2021-21852 includes multiple exploitable integer overflow vulnerabilities within the MPEG-4 decoding functionality.
Which software is affected by CVE-2021-21852?
CVE-2021-21852 affects versions of the GPAC library and certain packages like ccextractor up to version 0.88+ds1-1.
Can CVE-2021-21852 be exploited remotely?
Yes, CVE-2021-21852 can potentially be exploited remotely if a user processes a specially crafted MPEG-4 file.