CVE-2018-1000100
published 2018-03-06CVE-2018-1000100: GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks…
PriorityP434high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.11%
62.7th percentile
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | gpac | < gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye) | gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye) |
| debian | gpac | — | — |
| gpac | gpac | <= 0.7.1 | — |
| gpac | gpac | >= 0 < 0.5.2-426-gc5ad4e4+dfsg5-4.1 | 0.5.2-426-gc5ad4e4+dfsg5-4.1 |
| gpac | gpac | >= 0 < 0.5.2-426-gc5ad4e4+dfsg5-1ubuntu0.1 | 0.5.2-426-gc5ad4e4+dfsg5-1ubuntu0.1 |
| gpac | gpac | >= 0 < 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1 | 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1 |
| gpac | gpac | >= 0 < 0.5.0+svn4288~dfsg1-4ubuntu1+esm1 | 0.5.0+svn4288~dfsg1-4ubuntu1+esm1 |
| gpac_project | gpac | <= 0.7.1 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9p2f-3x2r-h24p: GPAC through 0
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2018-7752 [HIGH] CWE-119 GHSA-9p2f-3x2r-h24p: GPAC through 0
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
GHSA
GHSA-63xh-fh87-9c7q: GPAC MP4Box version 0
ghsa_unreviewed·2022-05-14
CVE-2018-1000100 [HIGH] CWE-119 GHSA-63xh-fh87-9c7q: GPAC MP4Box version 0
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.
OSV
CVE-2018-7752: GPAC through 0
osv·2018-03-07·CVSS 7.8
CVE-2018-7752 [HIGH] CVE-2018-7752: GPAC through 0
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
OSV
CVE-2018-1000100: GPAC MP4Box version 0
osv·2018-03-06·CVSS 7.8
CVE-2018-1000100 [HIGH] CVE-2018-1000100: GPAC MP4Box version 0
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.
Ubuntu
GPAC vulnerabilities
vendor_ubuntu·2019-03-29
CVE-2018-1000100 GPAC vulnerabilities
Title: GPAC vulnerabilities
Summary: GPAC could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that the GPAC MP4Box utility incorrectly handled certain
memory operations. If an user or automated system were tricked into opening a
specially crafted MP4 file, a remote attacker could use this issue to cause
MP4Box to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-7752: gpac - GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function i...
vendor_debian·2018·CVSS 7.8
CVE-2018-7752 [HIGH] CVE-2018-7752: gpac - GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function i...
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
Scope: local
bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
Debian
CVE-2018-1000100: gpac - GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability i...
vendor_debian·2018·CVSS 7.8
CVE-2018-1000100 [HIGH] CVE-2018-1000100: gpac - GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability i...
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-06
Published