Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-68761
HistoryAug 18, 2021 - 12:00 a.m.

GPAC has an unspecified vulnerability

2021-08-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
gpac
multimedia framework
integer overflow
mpeg-4
buffer overflow
memory corruption
security vulnerability
unchecked addition operations
exploitable vulnerability
cnvd

EPSS

0.003

Percentile

70.0%

A security vulnerability exists in GPAC Project Advanced Content, an open source multimedia framework, which stems from multiple exploitable integer overflow vulnerabilities in the MPEG-4 decoding functionality of Advanced Content. A specially crafted MPEG-4 file input could cause an integer overflow due to unchecked addition operations, which could be exploited by an attacker to cause a heap-based buffer overflow resulting in memory corruption.

EPSS

0.003

Percentile

70.0%