SB2021090115 - Debian update for gpac
Published: September 1, 2021 Updated: December 22, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 24 secuirty vulnerabilities.
1) Integer overflow (CVE-ID: CVE-2021-21834)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "co64" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Integer overflow (CVE-ID: CVE-2021-21848)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stz2” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
3) Integer overflow (CVE-ID: CVE-2021-21861)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "hdlr" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
4) Integer overflow (CVE-ID: CVE-2021-21860)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "trik" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
5) Integer overflow (CVE-ID: CVE-2021-21859)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stri" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
6) Integer overflow (CVE-ID: CVE-2021-21858)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "url" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
7) Integer overflow (CVE-ID: CVE-2021-21857)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "txtc" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
8) Integer overflow (CVE-ID: CVE-2021-21855)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "sdp" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
9) Integer overflow (CVE-ID: CVE-2021-21854)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "rtp" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
10) Integer overflow (CVE-ID: CVE-2021-21853)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "name" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
11) Integer overflow (CVE-ID: CVE-2021-21850)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "trun” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
12) Integer overflow (CVE-ID: CVE-2021-21849)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "tfra” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
13) Integer overflow (CVE-ID: CVE-2021-21847)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "“stts” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
14) Integer overflow (CVE-ID: CVE-2021-21836)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "ctts" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
15) Integer overflow (CVE-ID: CVE-2021-21846)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stsz” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
16) Integer overflow (CVE-ID: CVE-2021-21845)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stsc” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
17) Integer overflow (CVE-ID: CVE-2021-21844)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "stco” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
18) Integer overflow (CVE-ID: CVE-2021-21843)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "ssix” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
19) Integer overflow (CVE-ID: CVE-2021-21842)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "ssix” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
20) Integer overflow (CVE-ID: CVE-2021-21841)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "sbgp” decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
21) Integer overflow (CVE-ID: CVE-2021-21840)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "saio" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
22) Integer overflow (CVE-ID: CVE-2021-21839)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "pcrb" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
23) Integer overflow (CVE-ID: CVE-2021-21838)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "fpar" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
24) Integer overflow (CVE-ID: CVE-2021-21837)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the MPEG-4 decoding functionality within the "fecr" decoder. A remote attacker can trick a victim to open a video, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.