PT-2020-14781 · Gopro · Gpmf-Parser

Published

2020-10-19

·

Updated

2020-10-29

·

CVE-2020-16159

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions GoPro gpmf-parser version 1.5
Description The issue is related to a heap out-of-bounds read and segfault in the GPMF ScaledData() function. Parsing malicious input can result in a crash or information disclosure.
Recommendations For GoPro gpmf-parser version 1.5, update to a newer version that contains a fix for this issue to prevent potential crashes or information disclosure.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16159

Affected Products

Gpmf-Parser