Denial of Service Vulnerability in MP4Box by GPAC
CVE-2021-41456
7.5HIGH
What is CVE-2021-41456?
A stack buffer overflow exists in the MP4Box application, specifically in the nhmldmx_send_sample()
function located in the source file src/filters/dmx_nhml.c
. This vulnerability can be exploited through the szXmlTo
parameter, resulting in denial of service conditions. Attackers could craft malicious input that triggers this overflow, potentially leading to crashes or unavailability of the service.