cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 3 of 10
CVE-2022-45283P3HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-45283 [HIGH] CVE-2022-45283: gpac - GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_... GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2018-20762P3HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-20762 [HIGH] CVE-2018-20762: gpac - GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_mu... GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2018-20760P3HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-20760 [HIGH] CVE-2018-20760: gpac - In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in... In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2022-1441P3HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-1441 [HIGH] CVE-2022-1441: gpac - MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package ... MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow. Scope:
debian
CVE-2022-26967P3HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-26967 [HIGH] CVE-2022-26967: gpac - GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be trig... GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-45202P3HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-45202 [HIGH] CVE-2022-45202: gpac - GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflo... GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2019-13618P4HIGHCVSS 7.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-13618 [HIGH] CVE-2019-13618: ccextractor - In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer ... In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c. Scope: local bullseye: open
debian
CVE-2018-7752P3HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-7752 [HIGH] CVE-2018-7752: gpac - GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function i... GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2018-13005P4CRITICALCVSS 9.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-13005 [CRITICAL] CVE-2018-13005: gpac - An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomed... An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2018-13006P4CRITICALCVSS 9.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-13006 [CRITICAL] CVE-2018-13006: gpac - An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer ov... An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2021-32268P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-2 (bullseye)2021
CVE-2021-32268 [HIGH] CVE-2021-32268: gpac - Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before... Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbitrary code. The fixed version is 1.0.1. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2022-24577P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-24577 [HIGH] CVE-2022-24577: gpac - GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8... GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.) Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-35979P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4 (bullseye)2020
CVE-2020-35979 [HIGH] CVE-2020-35979: gpac - An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buf... An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2019-12482P4HIGHCVSS 7.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-12482 [HIGH] CVE-2019-12482: ccextractor - An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in th... An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box. Scope: local bullseye: open
debian
CVE-2021-36412P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-36412 [HIGH] CVE-2021-36412: gpac - A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via th... A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command, Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-38530P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-38530 [HIGH] CVE-2022-38530: gpac - GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflo... GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-1449P3MEDIUMCVSS 5.3fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-1449 [MEDIUM] CVE-2023-1449: gpac - A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and class... A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommende
debian
CVE-2020-19751P4CRITICALCVSS 9.1fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-19751 [CRITICAL] CVE-2020-19751: ccextractor - An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_... An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read. Scope: local bullseye: open
debian
CVE-2021-40574P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40574 [HIGH] CVE-2021-40574: gpac - The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerab... The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-36417P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-36417 [HIGH] CVE-2021-36417: gpac - A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_... A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
Debian Gpac vulnerabilities | cvebase