Vulnerability Details CVE-2022-24249
A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which causes a Denial of Service. This vulnerability was fixed in commit 71f9871.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.5%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2022-24249
-
-
cpe:2.3:a:gpac:gpac:0.5.2
-
cpe:2.3:a:gpac:gpac:0.6.0
-
cpe:2.3:a:gpac:gpac:0.6.1
-
cpe:2.3:a:gpac:gpac:0.7.0
-
cpe:2.3:a:gpac:gpac:0.7.1
-
cpe:2.3:a:gpac:gpac:0.8.0
-
cpe:2.3:a:gpac:gpac:0.9.0
-
Gpac
»
Gpac
»
Version: 0.9.0-development-20191109
cpe:2.3:a:gpac:gpac:0.9.0-development-20191109
-
-
cpe:2.3:a:gpac:gpac:1.0.1
-
cpe:2.3:a:gpac:gpac:1.1.0
-
Gpac
»
Gpac
»
Version: 1.1.0-dev-rev1663-g881c6a94a-master
cpe:2.3:a:gpac:gpac:1.1.0-dev-rev1663-g881c6a94a-master
-
Gpac
»
Gpac
»
Version: 1.1.0-dev-rev1727-g8be34973d-master
cpe:2.3:a:gpac:gpac:1.1.0-dev-rev1727-g8be34973d-master
-
Gpac
»
Gpac
»
Version: 1.1.0-dev-rev1759-geb2d1e6dd
cpe:2.3:a:gpac:gpac:1.1.0-dev-rev1759-geb2d1e6dd
-