PT-2020-10606 · Gpac+1 · Gpac+1

Strongcourage

·

Published

2018-12-19

·

Updated

2020-03-25

·

CVE-2019-20630

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC versions prior to 0.8.0
Description A heap-based buffer over-read issue exists in the BS ReadByte function, which is called from gf bs read bit in utils/bitstream.c. This can cause a denial of service when a crafted MP4 file is processed.
Recommendations For versions prior to 0.8.0, update to version 0.8.0 or later to resolve the issue.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
CVE-2019-20630

Affected Products

Alt Linux
Gpac