CVE-2020-22674NULL Pointer Dereference in Gpac

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 52.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 12
Latest updateMay 24

Description

An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_intern.c, which allows attackers to cause a denial of service (DoS) via a crafted input.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/gpac< gpac 1.0.1+dfsg1-2 (bullseye)
Debiangpac/gpac< 1.0.1+dfsg1-2
NVDgpac/gpac0.8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wrmr-hgjg-7q2j: An issue was discovered in gpac 02022-05-24
OSV
CVE-2020-22674: An issue was discovered in gpac 02021-10-12

📋Vendor Advisories

1
Debian
CVE-2020-22674: gpac - An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in t...2020