CVE-2020-22352: Null Pointer Dereference
Published Aug 4, 2021
·Updated
The gfdashsegmenterprobeinput function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Affected Software
1 affected component
Gpac GPAC=0.8.0
Event History
Aug 4, 2021
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22352?
CVE-2020-22352 has a severity rating of medium due to its potential for denial of service.
2
How do I fix CVE-2020-22352?
To fix CVE-2020-22352, update GPAC to the latest version that addresses the NULL pointer dereference vulnerability.
3
What versions of GPAC are affected by CVE-2020-22352?
CVE-2020-22352 affects GPAC version 0.8.0 specifically.
4
What attackers can do with CVE-2020-22352?
Attackers can exploit CVE-2020-22352 to cause a denial of service by supplying a crafted MP4 file.
5
What is the function involved in CVE-2020-22352?
The vulnerability in CVE-2020-22352 is due to the gf_dash_segmenter_probe_input function in GPAC.