CVE-2023-3012: NULL Pointer Dereference in gpac/gpac
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gpacto a version that resolves this vulnerability.Fixed in 1.0.1+dfsg1-4+deb11u3
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3012?
The severity of CVE-2023-3012 is high with a CVSS score of 7.8.
What is the vulnerability description of CVE-2023-3012?
CVE-2023-3012 is a NULL Pointer Dereference vulnerability found in the GitHub repository gpac/gpac prior to version 2.2.2.
Which software is affected by CVE-2023-3012?
The affected software includes gpac package versions 0.5.2-426-gc5ad4e4+dfsg5-5 up to 2.2.1+dfsg1-3 in Debian, and GPAC versions up to 2.2.2.
How can I fix CVE-2023-3012?
To fix CVE-2023-3012, update to version 2.2.2 or later for gpac/gpac.
Where can I find more information about CVE-2023-3012?
More information about CVE-2023-3012 can be found at the following references: [GitHub Commit](https://github.com/gpac/gpac/commit/53387aa86c1af1228d0fa57c67f9c7330716d5a7), [Huntr](https://huntr.dev/bounties/916b787a-c603-409d-afc6-25bb02070e69), and [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-3012).