CVE-2021-45297: Medium severity gpac mp4box vulnerability
Published Dec 21, 2021
·Updated
An infinite loop vulnerability exists in Gpac 1.0.1 in gfgetbitsize.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.1.0
Event History
Dec 21, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-45297.
2
What is the title of this vulnerability?
The title of this vulnerability is 'An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.'
3
What is the description of this vulnerability?
The description of this vulnerability is 'An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.'
4
Which software is affected by this vulnerability?
The Gpac software versions 1.0.1 and 2.0.0 are affected by this vulnerability.
5
How can I fix this vulnerability?
To fix this vulnerability, update the Gpac software to version 1.0.1+dfsg1-4+deb11u3 or 2.0.0+dfsg1-4.