[Git][security-tracker-team/security-tracker][master] Add CVE-2021-4043/gpac

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Feb 7 20:59:19 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
26dd6a0e by Salvatore Bonaccorso at 2022-02-07T21:57:59+01:00
Add CVE-2021-4043/gpac

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13384,7 +13384,9 @@ CVE-2021-4044 (Internally libssl in OpenSSL calls X509_verify_cert() on the clie
 	- openssl <not-affected> (Vulnerable code not present)
 	NOTE: https://www.openssl.org/news/secadv/20211214.txt
 CVE-2021-4043 (NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0 ...)
-	TODO: check
+	- gpac <unfixed>
+	NOTE: https://huntr.dev/bounties/d7a534cb-df7a-48ba-8ce3-46b1551a9c47
+	NOTE: https://github.com/gpac/gpac/commit/64a2e1b799352ac7d7aad1989bc06e7b0f2b01db
 CVE-2021-4042
 	RESERVED
 CVE-2021-4041 [Improper shell escaping in ansible-runner]



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/26dd6a0e57361719785c2442bb358788ee9c8b1b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/26dd6a0e57361719785c2442bb358788ee9c8b1b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220207/570a5f0b/attachment.htm>


More information about the debian-security-tracker-commits mailing list