First published: Thu May 30 2019(Updated: )
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GPAC MP4Box | =0.7.1 | |
GPAC MP4Box | >=0.6.1<=0.7.1 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12481 has a severity rating of medium due to potential exploitation leading to application crashes.
To fix CVE-2019-12481, upgrade GPAC to version 0.7.2 or later, where the NULL pointer dereference issue has been addressed.
The potential impacts of CVE-2019-12481 include application instability and denial of service due to crashes.
GPAC version 0.7.1 is specifically affected by CVE-2019-12481.
There is no public information indicating that CVE-2019-12481 is actively exploited in the wild.