PT-2022-13892 · Gpac · Gpac

Xidoo123

·

Published

2022-04-25

·

Updated

2023-06-27

·

CVE-2022-1441

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPAC versions 2.0.0
Description The issue arises when MP4Box, a component of GPAC, attempts to parse a MP4 file. It calls the function diST box read() to read from the video, allocating a buffer str with a fixed length. However, the content read from bs and its length are controllable by the user, leading to a buffer overflow.
Recommendations For GPAC version 2.0.0, consider disabling the diST box read() function as a temporary workaround until a patch is available. Restrict access to MP4Box to minimize the risk of exploitation. Avoid using MP4Box to parse MP4 files from untrusted sources until the issue is resolved.

Exploit

Fix

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-1441
DSA-5411-1

Affected Products

Gpac