CVE-2022-36191
published 2022-08-17CVE-2022-36191: A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.36%
28.4th percentile
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gpac | < gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) | gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) |
| gpac | gpac | < 2.2.0 | 2.2.0 |
| gpac | gpac | >= 0 < 1.0.1+dfsg1-4+deb11u2 | 1.0.1+dfsg1-4+deb11u2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GPAC MP4Box isomedia/avc_ext.c gf_isom_dovi_config_get heap-based overflow (Issue 2218 / fef6242)
vuldb·2026-06-16·CVSS 5.5
CVE-2022-36191 [MEDIUM] GPAC MP4Box isomedia/avc_ext.c gf_isom_dovi_config_get heap-based overflow (Issue 2218 / fef6242)
A vulnerability classified as critical has been found in GPAC. This issue affects the function gf_isom_dovi_config_get of the file isomedia/avc_ext.c of the component MP4Box. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2022-36191. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-r3c7-v6q7-j6rm: A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext
ghsa_unreviewed·2022-08-18
CVE-2022-36191 [MEDIUM] CWE-787 GHSA-r3c7-v6q7-j6rm: A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
OSV
CVE-2022-36191: A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext
osv·2022-08-17·CVSS 5.5
CVE-2022-36191 [MEDIUM] CVE-2022-36191: A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
Debian
CVE-2022-36191: gpac - A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isome...
vendor_debian·2022·CVSS 5.5
CVE-2022-36191 [MEDIUM] CVE-2022-36191: gpac - A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isome...
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-17
Published