Vulnerability Details CVE-2021-40574
The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-40574
-
cpe:2.3:a:gpac:gpac:0.9.0
-
Gpac
»
Gpac
»
Version: 0.9.0-development-20191109
cpe:2.3:a:gpac:gpac:0.9.0-development-20191109
-
-
cpe:2.3:a:gpac:gpac:1.0.1