Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption The implementation of the parser used for the “Xtra” FOURCC code is handled. An attacker can convince a user to open a video to trigger this vulnerability.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1298 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: talos
Published: 2021-08-18T14:25:00
Updated: 2021-08-18T14:25:00
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-21862
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-08-18T15:15:07.767
Modified: 2022-07-29T14:11:59.147
Link: CVE-2021-21862
JSON object: View
Redhat Information
No data.