SB2021090115 - Debian update for gpac



SB2021090115 - Debian update for gpac

Published: September 1, 2021 Updated: December 22, 2022

Security Bulletin ID SB2021090115
Severity
High
Patch available
YES
Number of vulnerabilities 24
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 24 secuirty vulnerabilities.


1) Integer overflow (CVE-ID: CVE-2021-21834)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "co64" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Integer overflow (CVE-ID: CVE-2021-21848)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stz2” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


3) Integer overflow (CVE-ID: CVE-2021-21861)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "hdlr" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


4) Integer overflow (CVE-ID: CVE-2021-21860)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "trik" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


5) Integer overflow (CVE-ID: CVE-2021-21859)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stri" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


6) Integer overflow (CVE-ID: CVE-2021-21858)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "url" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


7) Integer overflow (CVE-ID: CVE-2021-21857)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "txtc" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


8) Integer overflow (CVE-ID: CVE-2021-21855)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "sdp" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


9) Integer overflow (CVE-ID: CVE-2021-21854)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "rtp" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


10) Integer overflow (CVE-ID: CVE-2021-21853)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "name" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


11) Integer overflow (CVE-ID: CVE-2021-21850)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "trun” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


12) Integer overflow (CVE-ID: CVE-2021-21849)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "tfra” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


13) Integer overflow (CVE-ID: CVE-2021-21847)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "“stts” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


14) Integer overflow (CVE-ID: CVE-2021-21836)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "ctts" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


15) Integer overflow (CVE-ID: CVE-2021-21846)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stsz” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


16) Integer overflow (CVE-ID: CVE-2021-21845)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stsc” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


17) Integer overflow (CVE-ID: CVE-2021-21844)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stco” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


18) Integer overflow (CVE-ID: CVE-2021-21843)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "ssix” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


19) Integer overflow (CVE-ID: CVE-2021-21842)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "ssix” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


20) Integer overflow (CVE-ID: CVE-2021-21841)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "sbgp” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


21) Integer overflow (CVE-ID: CVE-2021-21840)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "saio" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


22) Integer overflow (CVE-ID: CVE-2021-21839)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "pcrb" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


23) Integer overflow (CVE-ID: CVE-2021-21838)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "fpar" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


24) Integer overflow (CVE-ID: CVE-2021-21837)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "fecr" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.