CVE-2020-35980Use After Free in Gpac

CWE-416Use After Free4 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 67.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 21
Latest updateMay 24

Description

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/gpac< gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)
Debiangpac/gpac< 1.0.1+dfsg1-4+deb11u2
NVDgpac/gpac0.8.0, 1.0.1+1
debiandebian/ccextractor< gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-842w-qv52-hpw3: An issue was discovered in GPAC version 02022-05-24
OSV
CVE-2020-35980: An issue was discovered in GPAC version 02021-04-21

📋Vendor Advisories

1
Debian
CVE-2020-35980: ccextractor - An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-fr...2020
CVE-2020-35980 — Use After Free in Debian Gpac | cvebase