PT-2022-23251 · Gpac+1 · Gpac+1

Janette88

·

Published

2018-12-19

·

Updated

2023-05-27

·

CVE-2022-36191

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC versions prior to the version that includes commit fef6242
Description A heap-buffer-overflow occurred in the gf isom dovi config get function of isomedia/avc ext.c at line 2490, as demonstrated by MP4Box.
Recommendations For versions prior to the one including commit fef6242, update to a version that includes this commit to resolve the issue. As a temporary workaround, consider restricting access to the gf isom dovi config get function until a patch is available.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
CVE-2022-36191
DSA-5411-1

Affected Products

Alt Linux
Gpac