Security Advisory

CVE-2021-40592

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-08 00:00:00
Last updated 2024-08-04 02:44:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file.