CVE-2021-40566
 
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service.
Se presenta un fallo de segmentación causado por una vulnerabilidad de uso de memoria previamente liberada de la pila en Gpac versiones hasta 1.0.1, por medio de la función mpgviddmx_process en el archivo reframe_mpgvid.c cuando es usado mp4box, que causa una denegación de servicio
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-09-07 CVE Reserved
- 2022-01-12 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/gpac/gpac/issues/1887 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/gpac/gpac/commit/96047e0e6166407c40cc19f4e94fb35cd7624391 | 2023-05-27 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2023/dsa-5411 | 2023-05-27 |