CVE-2021-21856: Buffer Overflow
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21856?
CVE-2021-21856 has a high severity due to potential remote code execution from an integer overflow.
How do I fix CVE-2021-21856?
To fix CVE-2021-21856, update to the latest version of the GPAC library that addresses this vulnerability.
What software is affected by CVE-2021-21856?
CVE-2021-21856 affects GPAC version 1.0.1 and prior versions.
What types of attacks can CVE-2021-21856 facilitate?
CVE-2021-21856 can facilitate heap-based buffer overflow attacks leading to potential code execution.
Is there a workaround for CVE-2021-21856?
There are no known workarounds for CVE-2021-21856; upgrading the software is recommended.