CVE-2024-0322
published 2024-01-08CVE-2024-0322: Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
PriorityP336critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.95%
57.3th percentile
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gpac | — | — |
| gpac | gpac | < 2.3.0 | 2.3.0 |
| gpac | gpac | — | — |
| gpac | gpac | >= 0 < 0.5.0+svn4288~dfsg1-4ubuntu1+esm2 | 0.5.0+svn4288~dfsg1-4ubuntu1+esm2 |
| gpac | gpac | >= 0 < 0.5.2-426-gc5ad4e4+dfsg5-1ubuntu0.1+esm2 | 0.5.2-426-gc5ad4e4+dfsg5-1ubuntu0.1+esm2 |
| gpac | gpac | >= 0 < 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1+esm1 | 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1+esm1 |
| gpac | gpac | >= 0 < 0.5.2-426-gc5ad4e4+dfsg5-5ubuntu0.1~esm2 | 0.5.2-426-gc5ad4e4+dfsg5-5ubuntu0.1~esm2 |
| gpac | gpac | >= 0 < 2.0.0+dfsg1-2ubuntu0.1~esm2 | 2.0.0+dfsg1-2ubuntu0.1~esm2 |
| gpac | gpac | >= 0 < 2.2.1+dfsg1-3.1ubuntu0.1~esm2 | 2.2.1+dfsg1-3.1ubuntu0.1~esm2 |
| gpac | gpac_gpac | >= unspecified < 2.3-DEV | 2.3-DEV |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_ubuntu7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GPAC vulnerabilities
vendor_ubuntu·2025-03-04·CVSS 7.7
CVE-2024-0322 [HIGH] GPAC vulnerabilities
Title: GPAC vulnerabilities
Summary: Several security issues were fixed in GPAC.
It was discovered that the GPAC MP4Box utility incorrectly handled certain
AC3 files, which could lead to an out-of-bounds read. A remote attacker
could use this issue to cause MP4Box to crash, resulting in a denial of
service (system crash). This issue only affected Ubuntu 22.04 LTS and
Ubuntu 24.04 LTS. (CVE-2023-5520, CVE-2024-0322)
It was discovered that the GPAC MP4Box utility incorrectly handled certain
malformed text files. If a user or automated system using MP4Box were
tricked into opening a specially crafted RST file, an attacker could use
this issue to cause a denial of service (system crash) or execute arbitrary
code. (CVE-2024-0321)
Instructions: In general, a standard system update will make
Debian
CVE-2024-0322: gpac - Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
vendor_debian·2024·CVSS 9.1
CVE-2024-0322 [CRITICAL] CVE-2024-0322: gpac - Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
Scope: local
bullseye: open
OSV
gpac vulnerabilities
osv·2025-03-04·CVSS 7.7
CVE-2023-5520 [HIGH] gpac vulnerabilities
gpac vulnerabilities
It was discovered that the GPAC MP4Box utility incorrectly handled certain
AC3 files, which could lead to an out-of-bounds read. A remote attacker
could use this issue to cause MP4Box to crash, resulting in a denial of
service (system crash). This issue only affected Ubuntu 22.04 LTS and
Ubuntu 24.04 LTS. (CVE-2023-5520, CVE-2024-0322)
It was discovered that the GPAC MP4Box utility incorrectly handled certain
malformed text files. If a user or automated system using MP4Box were
tricked into opening a specially crafted RST file, an attacker could use
this issue to cause a denial of service (system crash) or execute arbitrary
code. (CVE-2024-0321)
OSV
CVE-2024-0322: Out-of-bounds Read in GitHub repository gpac/gpac prior to 2
osv·2024-01-08·CVSS 9.1
CVE-2024-0322 [CRITICAL] CVE-2024-0322: Out-of-bounds Read in GitHub repository gpac/gpac prior to 2
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
GHSA
GHSA-27gj-wf7m-cw9x: Out-of-bounds Read in GitHub repository gpac/gpac prior to 2
ghsa_unreviewed·2024-01-08
CVE-2024-0322 [MEDIUM] CWE-125 GHSA-27gj-wf7m-cw9x: Out-of-bounds Read in GitHub repository gpac/gpac prior to 2
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-01-08
Published