PT-2022-11278 · Gpac+1 · Gpac+1

·

CVE-2021-40609

·

Published

2018-12-19

·

Updated

2023-05-27

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC version 1.0.1
Description The issue allows attackers to cause a denial of service via a crafted file in the MP4Box command, specifically through the GetHintFormat function.
Recommendations For GPAC version 1.0.1, consider disabling the GetHintFormat function as a temporary workaround until a patch is available. Restrict access to the MP4Box command to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
CVE-2021-40609
DSA-5411-1

Affected Products

Alt Linux
Gpac