CVE-2021-40942: Medium severity gpac mp4box vulnerability
Published Jun 27, 2022
·Updated
In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filterparsedynargs function in filtercore/filter.c:1454, as demonstrated by GPAC. This can cause a denial of service (DOS).
Affected Software
1 affected component
Gpac GPAC=1.1.0
Remediation
Patch Available
Event History
Jun 27, 2022
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40942?
CVE-2021-40942 is classified as a high-severity vulnerability due to the potential for denial of service.
2
What causes CVE-2021-40942?
CVE-2021-40942 is caused by a heap-buffer-overflow in the filter_parse_dyn_args function in GPAC MP4Box v1.1.0.
3
How do I fix CVE-2021-40942?
To mitigate CVE-2021-40942, upgrade GPAC to a version later than 1.1.0 that addresses this vulnerability.
4
What impact does CVE-2021-40942 have on GPAC users?
CVE-2021-40942 can lead to a denial of service, affecting the availability of the affected software for users.
5
Which version of GPAC is vulnerable to CVE-2021-40942?
Only GPAC version 1.1.0 is known to be vulnerable to CVE-2021-40942.