CVE Vulnerabilities

CVE-2020-35981

NULL Pointer Dereference

Published: Apr 21, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Gpac Gpac 0.8.0 (including) 0.8.0 (including)
Gpac Gpac 1.0.1 (including) 1.0.1 (including)
Gpac Ubuntu bionic *
Gpac Ubuntu focal *
Gpac Ubuntu groovy *
Gpac Ubuntu hirsute *
Gpac Ubuntu impish *
Gpac Ubuntu kinetic *
Gpac Ubuntu lunar *
Gpac Ubuntu trusty *
Gpac Ubuntu trusty/esm *
Gpac Ubuntu xenial *

Potential Mitigations

References