The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5411-1 | gpac security update |
EUVD |
EUVD-2021-27749 | The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 05 Mar 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. | The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-05T23:03:49.310Z
Reserved: 2021-09-07T00:00:00.000Z
Link: CVE-2021-40574
No data.
Status : Modified
Published: 2022-01-13T19:15:08.317
Modified: 2025-03-05T23:15:13.557
Link: CVE-2021-40574
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD