CVE-2021-30020Out-of-bounds Write in Gpac

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 49.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateMay 24

Description

In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which with crafted file, pps->num_tile_columns may be larger than sizeof(pps->column_width), which results in a heap overflow in the loop.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/gpac< gpac 1.0.1+dfsg1-4 (bullseye)
Debiangpac/gpac< 1.0.1+dfsg1-4
NVDgpac/gpac1.0.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-865c-9wv7-4j76: In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers2022-05-24
OSV
CVE-2021-30020: In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers2021-04-19

📋Vendor Advisories

1
Debian
CVE-2021-30020: gpac - In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers....2021