Vulnerability Description
A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gpac | Gpac | 0.8.0 |
Related Weaknesses (CWE)
References
- https://github.com/gpac/gpac/commit/8e585e623b1d666b4ef736ed609264639cb27701PatchThird Party Advisory
- https://github.com/gpac/gpac/issues/1406Third Party Advisory
- https://github.com/gpac/gpac/commit/8e585e623b1d666b4ef736ed609264639cb27701PatchThird Party Advisory
- https://github.com/gpac/gpac/issues/1406Third Party Advisory
FAQ
What is CVE-2020-25427?
CVE-2020-25427 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service.
How severe is CVE-2020-25427?
CVE-2020-25427 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25427?
Check the references section above for vendor advisories and patch information. Affected products include: Gpac Gpac.