|Description||The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)|
Vulnerable and fixed packages
The table below lists information on source packages.
|bullseye (security), bullseye||1.0.1+dfsg1-4+deb11u1||vulnerable|
The information below is based on the following data on fixed versions.
[bullseye] - gpac <ignored> (Minor issue)
[buster] - gpac <ignored> (Minor issue)
[stretch] - gpac <ignored> (Minor issue)
[bullseye] - ccextractor <not-affected> (Vulnerable code introduced later)
[buster] - ccextractor <not-affected> (Vulnerable code introduced later)
The POC from the GitHub issue produces a SIGSEV in the stretch/buster version of gpac, but in an entirely different call chain; it appears to be a different issue altogether
It isn't clear if that means this CVE doesn't apply to stretch/buster, or if it is masking the issue with an earlier failure