CVE Vulnerabilities

CVE-2021-40592

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 08, 2022 | Modified: May 27, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition (infinite loop) vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Gpac Gpac * 1.0.1 (excluding)
Gpac Ubuntu bionic *
Gpac Ubuntu impish *
Gpac Ubuntu kinetic *
Gpac Ubuntu lunar *
Gpac Ubuntu trusty/esm *

References