CVE-2021-44920Improper Restriction of Operations within the Bounds of a Memory Buffer in Gpac

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 64.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 21
Latest updateDec 22

Description

An invalid memory address dereference vulnerability exists in gpac 1.1.0 in the dump_od_to_saf.isra function, which causes a segmentation fault and application crash.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDgpac/gpac1.1.0
debiandebian/gpac

🔴Vulnerability Details

2
GHSA
GHSA-4m3h-rj32-5f27: An invalid memory address dereference vulnerability exists in gpac 12021-12-22
OSV
CVE-2021-44920: An invalid memory address dereference vulnerability exists in gpac 12021-12-21

📋Vendor Advisories

1
Debian
CVE-2021-44920: gpac - An invalid memory address dereference vulnerability exists in gpac 1.1.0 in the ...2021
CVE-2021-44920 — Gpac vulnerability | cvebase