CVE-2021-45831: Null Pointer Dereference
Published Jan 5, 2022
·Updated
A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via strlenavx2, which causes a Denial of Service.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=1.0.1
Event History
Jan 5, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45831?
CVE-2021-45831 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2021-45831?
To mitigate CVE-2021-45831, upgrade GPAC to version 1.0.1+dfsg1-4+deb11u3 or 2.2.1+dfsg1-3.
3
Which versions of GPAC are affected by CVE-2021-45831?
GPAC version 1.0.1 and earlier versions up to 0.5.2-426-gc5ad4e4+dfsg5 are affected by CVE-2021-45831.
4
What causes the vulnerability in CVE-2021-45831?
CVE-2021-45831 is caused by a Null Pointer Dereference in the MP4Box component of GPAC.
5
What impact does CVE-2021-45831 have on systems?
CVE-2021-45831 may lead to a Denial of Service, causing the affected application to crash.