CVE-2021-45292: Null Pointer Dereference
Published Dec 21, 2021
·Updated
The gfisomhintrtpread function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.0.1
Event History
Dec 21, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45292?
CVE-2021-45292 has a severity level classified as a denial of service vulnerability.
2
How do I fix CVE-2021-45292?
To fix CVE-2021-45292, update GPAC to version 1.0.1+dfsg1-4+deb11u3 or 2.2.1+dfsg1-3.
3
What software is affected by CVE-2021-45292?
CVE-2021-45292 affects GPAC version 1.0.1 and earlier versions.
4
Can CVE-2021-45292 be exploited remotely?
Yes, CVE-2021-45292 can be exploited remotely through crafted files processed by GPAC.
5
What kind of impact does CVE-2021-45292 have on systems?
CVE-2021-45292 can lead to application crashes or interruption of service due to invalid memory access.