
Cloud Vulnerability DB
A community-led vulnerabilities database
A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which causes a Denial of Service. This vulnerability was fixed in commit 71f9871 (GITHUB).
The vulnerability occurs in the xtra_box_write function when handling XtraBox data. When prop_size is less than 4, data2 remains NULL and gets assigned to tag->prop_value. This NULL value is later passed to gf_bs_write_data() function, causing a null pointer dereference when attempting to access the memory (GITHUB).
The vulnerability can lead to a Denial of Service condition when processing specially crafted input files, as the null pointer dereference causes the application to crash (GITHUB).
The vulnerability can be triggered by providing a specially crafted file to MP4Box with the -hint parameter. A proof of concept exists demonstrating the crash through null pointer dereference (GITHUB).
The vulnerability has been fixed in commit 71f9871. Users should upgrade to a version containing this fix (GITHUB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."