CVE-2021-40568

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
13/01/2022
Last modified:
27/05/2023

Description

A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* 1.0.1 (including)