Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-68764
HistoryAug 18, 2021 - 12:00 a.m.

GPAC has an unspecified vulnerability

2021-08-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
gpac
multimedia framework
integer overflow
mpeg-4
buffer overflow
memory corruption
security vulnerability
open source

EPSS

0.002

Percentile

56.3%

A security vulnerability exists in GPAC Project Advanced Content, an open source multimedia framework, which stems from multiple exploitable integer overflow vulnerabilities in the MPEG-4 decoding functionality of Advanced Content. A specially crafted MPEG-4 file input could cause an integer overflow due to unchecked addition operations, which could be exploited by an attacker to cause a heap-based buffer overflow, resulting in memory corruption.