CVE-2021-45267NULL Pointer Dereference in Gpac

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 70.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 22
Latest updateDec 23

Description

An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/gpac< gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)
Debiangpac/gpac< 1.0.1+dfsg1-4+deb11u2
NVDgpac/gpac1.1.0

🔴Vulnerability Details

2
GHSA
GHSA-m2p2-7mfv-gh5x: An invalid memory address dereference vulnerability exists in gpac 12021-12-23
OSV
CVE-2021-45267: An invalid memory address dereference vulnerability exists in gpac 12021-12-22

📋Vendor Advisories

1
Debian
CVE-2021-45267: gpac - An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the...2021
CVE-2021-45267 — NULL Pointer Dereference in Gpac | cvebase