CVE-2021-32289: Null Pointer Dereference
Published Sep 20, 2021
·Updated
An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service.
Affected Software
1 affected component
Nokia Heif<=3.6.2
Remediation
Patch Available
Event History
Sep 20, 2021
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-32289.
2
What is the severity of CVE-2021-32289?
CVE-2021-32289 has a severity rating of medium.
3
What is the affected software?
The affected software is Nokia Heif version up to and including 3.6.2.
4
What is the CWE ID associated with CVE-2021-32289?
The CWE ID associated with CVE-2021-32289 is CWE-476.
5
Is there a fix available for CVE-2021-32289?
At the moment, a fix for CVE-2021-32289 is not available. Users should follow the recommendations provided by the vendor or project maintainers.