CVE-2021-45263: Use After Free
Published Dec 22, 2021
·Updated
An invalid free vulnerability exists in gpac 1.1.0 via the gfsvgdeleteattributevalue function, which causes a segmentation fault and application crash.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.1.0-dev
Event History
Dec 22, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-45263.
2
What is the affected software?
The affected software is gpac version 1.1.0.
3
How does this vulnerability occur?
This vulnerability occurs due to an invalid free in the gf_svg_delete_attribute_value function of gpac.
4
What is the impact of this vulnerability?
The impact of this vulnerability is a segmentation fault and application crash.
5
How can I fix this vulnerability?
To fix this vulnerability, update gpac to version 1.1.0 or later.