CVE-2021-40564: Null Pointer Dereference
Published Jan 12, 2022
·Updated
A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avcparseslice function in avparsers.c when using mp4box, which causes a denial of service.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC<=1.0.2
Remediation
Event History
Jan 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40564?
CVE-2021-40564 has a severity rating of medium due to its potential to cause a denial of service.
2
How do I fix CVE-2021-40564?
To fix CVE-2021-40564, upgrade to GPAC version 1.0.2 or later.
3
Which software is affected by CVE-2021-40564?
CVE-2021-40564 affects GPAC versions up to and including 1.0.2.
4
What causes the vulnerability in CVE-2021-40564?
The vulnerability in CVE-2021-40564 is caused by a null pointer dereference in the avc_parse_slice function.
5
What impact does CVE-2021-40564 have on systems?
CVE-2021-40564 can lead to a denial of service condition, impacting system availability.