CVE-2021-40944: Null Pointer Dereference
Published Jun 28, 2022
·Updated
In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gffilterpidgetpacket function in src/filtercore/filterpid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.1.0
Remediation
Patch Available
Event History
Jun 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40944?
CVE-2021-40944 is classified as a denial of service vulnerability because it can cause application crashes.
2
How do I fix CVE-2021-40944?
To address CVE-2021-40944, users should upgrade to GPAC version 1.1.0 or later.
3
Which software is affected by CVE-2021-40944?
CVE-2021-40944 specifically affects GPAC version 1.1.0.
4
What causes CVE-2021-40944?
CVE-2021-40944 is triggered by a null pointer reference in the gf_filter_pid_get_packet function.
5
Can CVE-2021-40944 be exploited remotely?
Yes, CVE-2021-40944 can be exploited remotely, potentially leading to service disruption.