NULL Pointer Dereference in HEIF Software by Nokia
CVE-2021-32289
5.5MEDIUM
What is CVE-2021-32289?
A vulnerability has been identified in Nokia's HEIF software, specifically in version 3.6.2 and earlier. This issue arises from a NULL pointer dereference in the convertByteStreamToRBSP() function found in nalutil.cpp. Exploitation of this vulnerability may allow an attacker to disrupt service, posing potential risks to systems utilizing this software.