CVE-2021-45291: Use After Free
Published Dec 21, 2021
·Updated
The gfdumpsetup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.0.1
Event History
Dec 21, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45291?
CVE-2021-45291 is classified as a denial of service vulnerability due to invalid memory address dereferencing.
2
How do I fix CVE-2021-45291?
To fix CVE-2021-45291, update GPAC to versions 1.0.1+dfsg1-4+deb11u3 or 2.2.1+dfsg1-3.
3
Which versions of GPAC are affected by CVE-2021-45291?
Versions of GPAC up to and including 1.0.1 are affected by CVE-2021-45291.
4
What specific function in GPAC is responsible for CVE-2021-45291?
The gf_dump_setup function in GPAC is responsible for the vulnerability identified as CVE-2021-45291.
5
Can CVE-2021-45291 be exploited remotely?
Yes, CVE-2021-45291 can potentially be exploited remotely through crafted files processed by the MP4Box command.