PT-2021-18661 · Gpac · Gpac

Treebacker

·

Published

2021-04-19

·

Updated

2021-04-21

·

CVE-2021-30199

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC version 1.0.1
Description The issue is related to a Null Pointer Dereference in the gf filter pck get data function, which can be triggered by a crafted mp4 file. This results in a crash when the first argument pck is null.
Recommendations For GPAC version 1.0.1, consider avoiding the use of crafted mp4 files that may cause the gf filter pck get data function to be called with a null pck argument until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-30199

Affected Products

Gpac