CVE-2021-21859

Publication date

2021-08-16 19:07:13

Family

talos

State

PUBLISHED

Description

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The stri_box_read function is used when processing atoms using the stri FOURCC code. An attacker can convince a user to open a video to trigger this vulnerability.