CVE-2021-28300

EUVD-2021-14989
NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
gpacgpac
0.5.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ccextractor
bullseye
vulnerable
buster
no-dsa
stretch
postponed
gpac
bullseye
1.0.1+dfsg1-4+deb11u3
fixed
bullseye (security)
1.0.1+dfsg1-4+deb11u3
fixed
buster
no-dsa
stretch
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gpac
bionic
needed
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
dne
noble
needed
trusty
needed
xenial
needed