CVE-2021-21852
Published: 18 August 2021
Summary
CVE-2021-21852 is a high-severity Integer Overflow to Buffer Overflow (CWE-680) vulnerability in Gpac Gpac. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 32.4% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-9023
Vulnerability details
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a…
more
heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.