CVE-2021-4043: Motion Spell GPAC Null Pointer Dereference Vulnerability
Published Feb 4, 2022
·Updated
Motion Spell GPAC contains a null pointer dereference vulnerability that could allow a local attacker to cause a denial-of-service (DoS) condition.
Other sources
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
Affected Software
4 affected componentsFixes available
debian/gpac
0.5.2-426-gc5ad4e4+dfsg5-51.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Motion Spell GPAC
Gpac GPAC<1.1.0
Debian Debian Linux=11.0
Remediation
Information
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Feb 4, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Sep 30, 2024
Known Exploited
via CISA·12:00 AM
Oct 3, 2024
News Published
via BleepingComputer·02:33 PM
News Published
via BleepingComputer·02:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-4043?
CVE-2021-4043 is classified as a high severity vulnerability due to its potential to cause a denial-of-service condition.
2
How do I fix CVE-2021-4043?
To fix CVE-2021-4043, upgrade the GPAC library to version 1.1.0 or later.
3
Who is affected by CVE-2021-4043?
CVE-2021-4043 affects users of GPAC versions prior to 1.1.0.
4
What type of vulnerability is CVE-2021-4043?
CVE-2021-4043 is a null pointer dereference vulnerability.
5
Can CVE-2021-4043 be exploited remotely?
CVE-2021-4043 requires local access to exploit the null pointer dereference vulnerability.