{"id":"CVE-2021-21860","details":"An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. The FOURCC code, 'trik', is parsed by the function within the library. An attacker can convince a user to open a video to trigger this vulnerability.","modified":"2026-05-15T12:04:09.023805552Z","published":"2021-08-16T20:15:48.550Z","database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","extracted_events":[{"last_affected":"11.0"}],"source":"CPE_FIELD","cpes":["cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4966"},{"type":"EVIDENCE","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2021-1298"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}