CVE-2021-45267: Null Pointer Dereference
Published Dec 22, 2021
·Updated
An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svgnodestart function, which causes a segmentation fault and application crash.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.1.0-dev
Event History
Dec 22, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45267?
CVE-2021-45267 has been classified as a high-severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2021-45267?
To fix CVE-2021-45267, upgrade gpac to a version that is above 1.1.0 or implement the patches provided by the vendor.
3
What kind of vulnerability is CVE-2021-45267?
CVE-2021-45267 is an invalid memory address dereference vulnerability that leads to a segmentation fault.
4
Which versions of gpac are affected by CVE-2021-45267?
Versions of gpac prior to 1.1.0 and some specific versions in the 2.x series are affected by CVE-2021-45267.
5
Can CVE-2021-45267 lead to data loss?
While CVE-2021-45267 primarily causes application crashes, improper handling could potentially lead to temporary data loss or corruption.