CVE-2021-28300: Null Pointer Dereference
NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28300?
CVE-2021-28300 has a high severity rating due to its potential to allow arbitrary code execution and cause Denial-of-Service conditions.
How do I fix CVE-2021-28300?
To fix CVE-2021-28300, you should update GPAC to version 0.5.2 or later, where the vulnerability is addressed.
What type of attack can be executed using CVE-2021-28300?
CVE-2021-28300 can be exploited by attackers to execute arbitrary code or create a Denial-of-Service by manipulating MP4 files.
Which versions of GPAC are affected by CVE-2021-28300?
CVE-2021-28300 specifically affects GPAC version 0.5.2.
What is the impact of CVE-2021-28300 on GPAC users?
The impact of CVE-2021-28300 on GPAC users includes potential system crashes or unauthorized code execution when handling malicious MP4 files.