CVE-2020-35982: Null Pointer Dereference
Published Apr 21, 2021
·Updated
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gfhintertrackfinalize() in mediatools/isomhinter.c.
Affected Software
2 affected components
Gpac GPAC=0.8.0
Gpac GPAC=1.0.1
Remediation
Event History
Apr 21, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35982?
CVE-2020-35982 is classified as a vulnerability that could lead to a denial of service due to an invalid pointer dereference.
2
How do I fix CVE-2020-35982?
To fix CVE-2020-35982, upgrade to GPAC version 0.8.1 or 1.0.2 or later, where the issue is resolved.
3
What versions of GPAC are affected by CVE-2020-35982?
CVE-2020-35982 affects GPAC versions 0.8.0 and 1.0.1.
4
What software is impacted by CVE-2020-35982?
GPAC versions 0.8.0 and 1.0.1 are impacted by CVE-2020-35982.
5
Is CVE-2020-35982 exploitable in any scenario?
CVE-2020-35982 can be exploited in scenarios where an attacker can manipulate input to trigger the invalid pointer dereference.