Lucene search

K
osvGoogleOSV:CVE-2021-21859
HistoryAug 16, 2021 - 8:15 p.m.

CVE-2021-21859

2021-08-1620:15:48
Google
osv.dev
7
integer truncation
gpac project
mpeg-4 decoding
vulnerability
fourcc code
video
exploitable

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

61.1%

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The stri_box_read function is used when processing atoms using the ‘stri’ FOURCC code. An attacker can convince a user to open a video to trigger this vulnerability.

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

61.1%