Name | CVE-2021-21856 |
Description | Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
gpac (PTS) | bullseye (security), bullseye | 1.0.1+dfsg1-4+deb11u3 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
gpac | source | (unstable) | (not affected) | | | |
Notes
- gpac <not-affected> (Vulnerable code not present)
Introduced in https://github.com/gpac/gpac/commit/35c4644cb5
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1299
https://github.com/gpac/gpac/commit/bbd741e0e5a6e7e1e90a73c350acc061dde9450b
https://github.com/gpac/gpac/issues/1814