CVE-2021-21853: Buffer Overflow
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21853?
CVE-2021-21853 is classified as a critical severity vulnerability due to the potential for remote code execution via a heap-based buffer overflow.
How do I fix CVE-2021-21853?
To mitigate CVE-2021-21853, users should upgrade to GPAC versions 0.5.2-426-gc5ad4e4+dfsg5-5, 1.0.1+dfsg1-4+deb11u3, or 2.2.1+dfsg1-3, which contain the necessary security patches.
What are the affected software versions for CVE-2021-21853?
CVE-2021-21853 affects GPAC version 1.0.1, as well as specific Debian distributions including Debian Linux 10.0 and 11.0.
How does CVE-2021-21853 exploit an integer overflow?
CVE-2021-21853 exploits an integer overflow through unchecked addition arithmetic in the MPEG-4 decoding functionality.
What kind of attack can CVE-2021-21853 facilitate?
CV-2021-21853 can facilitate remote code execution attacks, allowing attackers to execute arbitrary code on affected systems.