cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 2 of 10
CVE-2021-21840P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21840 [HIGH] CVE-2021-21840: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ... An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input used to process an atom using the “saio” FOURCC code cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attac
debian
CVE-2021-21861P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21861 [HIGH] CVE-2021-21861: gpac - An exploitable integer truncation vulnerability exists within the MPEG-4 decodin... An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user t
debian
CVE-2021-21860P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21860 [HIGH] CVE-2021-21860: gpac - An exploitable integer truncation vulnerability exists within the MPEG-4 decodin... An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. The FOURCC code, 'trik', is parsed by the function within the library. An
debian
CVE-2021-21849P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21849 [HIGH] CVE-2021-21849: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ... An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when the library encounters an atom using the “tfra” FOURCC code due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corr
debian
CVE-2021-21850P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21850 [HIGH] CVE-2021-21850: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ... An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when the library encounters an atom using the “trun” FOURCC code due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corr
debian
CVE-2021-28300P3CRITICALCVSS 9.8fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-28300 [CRITICAL] CVE-2021-28300: ccextractor - NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" funct... NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file. Scope: local bullseye: open
debian
CVE-2021-21859P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21859 [HIGH] CVE-2021-21859: gpac - An exploitable integer truncation vulnerability exists within the MPEG-4 decodin... An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The stri_box_read function is used when processing atoms using the 'stri' FOURCC code. An attacker can convince a user to open a video to trigger this vulnerability. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1
debian
CVE-2022-4202P3MEDIUMCVSS 6.3fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-4202 [MEDIUM] CVE-2022-4202: gpac - A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-... A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is b3d821c4ae9ba
debian
CVE-2020-11558P3CRITICALCVSS 9.8fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-11558 [CRITICAL] CVE-2020-11558: gpac - An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. a... An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2
debian
CVE-2022-36190P3CRITICALCVSS 9.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-36190 [CRITICAL] CVE-2022-36190: gpac - GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in func... GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-1795P3CRITICALCVSS 9.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-1795 [CRITICAL] CVE-2022-1795: gpac - Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV. Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2018-20763P3HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-20763 [HIGH] CVE-2018-20763: gpac - In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in... In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2023-1452P3MEDIUMCVSS 5.3fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-1452 [MEDIUM] CVE-2023-1452: gpac - A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been d... A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file filters/load_text.c. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to ap
debian
CVE-2023-1448P3MEDIUMCVSS 5.3fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-1448 [MEDIUM] CVE-2023-1448: gpac - A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-... A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-rev35-gbbca86917-master. This affects the function gf_m2ts_process_sdt of the file media_tools/mpegts.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch
debian
CVE-2019-11222P3HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-5 (bullseye)2019
CVE-2019-11222 [HIGH] CVE-2019-11222: gpac - gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue f... gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-5)
debian
CVE-2020-35980P3LOWCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2020
CVE-2020-35980 [HIGH] CVE-2020-35980: ccextractor - An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-fr... An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c. Scope: local bullseye: resolved
debian
CVE-2022-24578P3HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-24578 [HIGH] CVE-2022-24578: gpac - GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bi... GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-41459P3HIGHCVSS 7.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-41459 [HIGH] CVE-2021-41459: gpac - There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008... There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-41456P3HIGHCVSS 7.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-41456 [HIGH] CVE-2021-41456: gpac - There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004... There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-41457P3HIGHCVSS 7.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-41457 [HIGH] CVE-2021-41457: gpac - There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nh... There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
Debian Gpac vulnerabilities | cvebase