CVE-2022-1035: Segmentation Fault caused by MP4Box -lsr in gpac/gpac
Published Mar 21, 2022
·Updated
Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC<=2.0
Remediation
Event History
Mar 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1035?
CVE-2022-1035 has a severity rating that indicates it can lead to a segmentation fault affecting the stability of applications using MP4Box.
2
How do I fix CVE-2022-1035?
To fix CVE-2022-1035, upgrade to GPAC version 2.1.0-DEV or later, or use the specified fixed versions in Debian.
3
What versions of GPAC are affected by CVE-2022-1035?
CVE-2022-1035 affects GPAC versions up to and including 2.0.
4
Is CVE-2022-1035 a persistent vulnerability?
CVE-2022-1035 is not persistent; it triggers a segmentation fault during the use of MP4Box.
5
Can CVE-2022-1035 lead to system compromise?
While CVE-2022-1035 does not directly lead to system compromise, it can crash applications, potentially leading to denial of service.