5.5

CVE-2021-37231

Exploit
A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atomicparsley ProjectAtomicparsley Version20210124.204813.840499f
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.58
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://github.com/wez/atomicparsley/issues/30
Patch
Third Party Advisory
Exploit
https://github.com/wez/atomicparsley/pull/31#issue-687280335
Third Party Advisory
https://security.gentoo.org/glsa/202305-01