First published: Wed Apr 14 2021(Updated: )
NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GPAC MP4Box | =0.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28300 has a high severity rating due to its potential to allow arbitrary code execution and cause Denial-of-Service conditions.
To fix CVE-2021-28300, you should update GPAC to version 0.5.2 or later, where the vulnerability is addressed.
CVE-2021-28300 can be exploited by attackers to execute arbitrary code or create a Denial-of-Service by manipulating MP4 files.
CVE-2021-28300 specifically affects GPAC version 0.5.2.
The impact of CVE-2021-28300 on GPAC users includes potential system crashes or unauthorized code execution when handling malicious MP4 files.