CVE-2019-12481: Null Pointer Dereference
Published May 30, 2019
·Updated
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
Affected Software
3 affected components
Gpac GPAC=0.7.1
Gpac GPAC>=0.6.1<=0.7.1
Debian Debian Linux=8.0
Event History
May 30, 2019
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12481?
CVE-2019-12481 has a severity rating of medium due to potential exploitation leading to application crashes.
2
How do I fix CVE-2019-12481?
To fix CVE-2019-12481, upgrade GPAC to version 0.7.2 or later, where the NULL pointer dereference issue has been addressed.
3
What are the potential impacts of CVE-2019-12481?
The potential impacts of CVE-2019-12481 include application instability and denial of service due to crashes.
4
Which versions of GPAC are affected by CVE-2019-12481?
GPAC version 0.7.1 is specifically affected by CVE-2019-12481.
5
Is CVE-2019-12481 exploited in the wild?
There is no public information indicating that CVE-2019-12481 is actively exploited in the wild.