CVE-2022-1441
published 2022-04-25CVE-2022-1441: MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.96%
57.7th percentile
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gpac | < gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) | gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) |
| gpac | gpac | — | — |
| gpac | gpac | — | — |
| gpac | gpac | >= 0 < 1.0.1+dfsg1-4+deb11u2 | 1.0.1+dfsg1-4+deb11u2 |
| nodejs | undici | >= 0 < 5.8.0 | 5.8.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-1441: gpac - MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package ...
vendor_debian·2022·CVSS 7.8
CVE-2022-1441 [HIGH] CVE-2022-1441: gpac - MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package ...
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
GHSA
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
ghsa·2022-07-21·CVSS 9.8
CVE-2022-31151 [CRITICAL] CWE-346 undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
### Impact
Authorization headers are already cleared on cross-origin redirect in
https://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189, based on https://github.com/nodejs/undici/issues/872.
However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There also has been active discussion of implementing a cookie store https://github.com/nodejs/undici/pull/1441, which suggests that there are active users using cookie headers in undici.
As such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd part
GHSA
GHSA-vxc8-cmfv-782q: MP4Box is a component of GPAC-2
ghsa_unreviewed·2022-04-26
CVE-2022-1441 [HIGH] CWE-119 GHSA-vxc8-cmfv-782q: MP4Box is a component of GPAC-2
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.
OSV
CVE-2022-1441: MP4Box is a component of GPAC-2
osv·2022-04-25·CVSS 7.8
CVE-2022-1441 [HIGH] CVE-2022-1441: MP4Box is a component of GPAC-2
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gpac/gpac/commit/3dbe11b37d65c8472faf0654410068e5500b3adbhttps://github.com/gpac/gpac/issues/2175https://www.debian.org/security/2023/dsa-5411https://github.com/gpac/gpac/commit/3dbe11b37d65c8472faf0654410068e5500b3adbhttps://github.com/gpac/gpac/issues/2175https://www.debian.org/security/2023/dsa-5411
2022-04-25
Published