CVE-2021-21852
published 2021-08-18CVE-2021-21852: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.99%
78.4th percentile
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ccextractor | < gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) | gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) |
| debian | gpac | < gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) | gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) |
| gpac | gpac | — | — |
| gpac | gpac | >= 0 < 1.0.1+dfsg1-4+deb11u2 | 1.0.1+dfsg1-4+deb11u2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wx3-gv33-fjg8: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v
ghsa_unreviewed·2022-05-24
CVE-2021-21852 [HIGH] CWE-190 GHSA-4wx3-gv33-fjg8: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
OSV
CVE-2021-21852: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v
osv·2021-08-18·CVSS 8.8
CVE-2021-21852 [HIGH] CVE-2021-21852: Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Debian
CVE-2021-21852: ccextractor - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
vendor_debian·2021·CVSS 8.8
CVE-2021-21852 [HIGH] CVE-2021-21852: ccextractor - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple integer overflow vulnerabilities in GPAC Project on Advanced Content
blogs_talos·2021-08-13·CVSS 8.8
[HIGH] Vulnerability Spotlight: Multiple integer overflow vulnerabilities in GPAC Project on Advanced Content
## Vulnerability Spotlight: Multiple integer overflow vulnerabilities in GPAC Project on Advanced Content
A Cisco Talos team member discovered these vulnerabilities.
Cisco Talos recently discovered multiple integer overflow vulnerabilities in the GPAC Project on Advanced Content that could lead to memory corruption.
The GPAC Project on Advanced Content is an open-source cross-platform library that implements the MPEG-4 system standard and provides tools for media playback, vector graphics, and 3-D rendering. The project comes with the MP4Box tool, which allows the user to encode or decode media containers in multiple supported formats.
TALOS-2021-1297 (CVE-2021-21834 - CVE-2021-21852), TALOS-2021-1298 (CVE-2021-21859 - CVE-2021-21862) and TALOS-2021-1299 (CVE-2021-21853 - CVE-2021-2185
Talos
Vulnerability Spotlight: Multiple integer overflow vulnerabilities in GPAC Project on Advanced Content
blogs_talos·2021-08-13·CVSS 8.8
[HIGH] Vulnerability Spotlight: Multiple integer overflow vulnerabilities in GPAC Project on Advanced Content
A Cisco Talos team member discovered these vulnerabilities.
Cisco Talos recently discovered multiple integer overflow vulnerabilities in the GPAC Project on Advanced Content that could lead to memory corruption.
The GPAC Project on Advanced Content is an open-source cross-platform library that implements the MPEG-4 system standard and provides tools for media playback, vector graphics, and 3-D rendering. The project comes with the MP4Box tool, which allows the user to encode or decode media containers in multiple supported formats.
TALOS-2021-1297 (CVE-2021-21834 - CVE-2021-21852), TALOS-2021-1298 (CVE-2021-21859 - CVE-2021-21862) and TALOS-2021-1299 (CVE-2021-21853 - CVE-2021-21858) could all allow an adversary to corrupt the memory of the application. An adversary could exploit these
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1297https://www.debian.org/security/2023/dsa-5411https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1297https://talosintelligence.com/vulnerability_reports/TALOS-2021-1297https://www.debian.org/security/2023/dsa-5411https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1297
2021-08-18
Published