CVE-2021-40565: Null Pointer Dereference
Published Jan 12, 2022
·Updated
A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gfavcparsenalu function in avparsers.c when using mp4box, which causes a denial of service.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC<=1.0.1
Remediation
Event History
Jan 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40565?
CVE-2021-40565 is classified as a denial of service vulnerability due to a segmentation fault caused by a null pointer dereference.
2
How do I fix CVE-2021-40565?
To mitigate CVE-2021-40565, upgrade Gpac to version 1.0.1+dfsg1-4+deb11u3 or 2.2.1+dfsg1-3.
3
Which versions of Gpac are affected by CVE-2021-40565?
CVE-2021-40565 affects Gpac versions up to and including 1.0.1.
4
What causes the CVE-2021-40565 vulnerability?
CVE-2021-40565 is caused by a null pointer dereference within the gf_avc_parse_nalu function.
5
Is CVE-2021-40565 specific to any operating system?
CVE-2021-40565 has been specifically noted in Debian distributions that include the affected versions of Gpac.