cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 4 of 10
CVE-2020-35981P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4 (bullseye)2020
CVE-2020-35981 [HIGH] CVE-2020-35981: ccextractor - An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid poi... An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c. Scope: local bullseye: open
debian
CVE-2020-35982P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4 (bullseye)2020
CVE-2020-35982 [HIGH] CVE-2020-35982: gpac - An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid poi... An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-32271P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-2 (bullseye)2021
CVE-2021-32271 [HIGH] CVE-2021-32271: gpac - An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists... An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-29279P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-29279 [HIGH] CVE-2021-29279: gpac - There is a integer overflow in function filter_core/filter_props.c:gf_props_assi... There is a integer overflow in function filter_core/filter_props.c:gf_props_assign_value in GPAC 1.0.1. In which, the arg const GF_PropertyValue *value,maybe value->value.data.size is a negative number. In result, memcpy in gf_props_assign_value failed. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2023-0770P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-0770 [HIGH] CVE-2023-0770: gpac - Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2. Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47095P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47095 [HIGH] CVE-2022-47095: gpac - GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_p... GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47663P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47663 [HIGH] CVE-2022-47663: gpac - GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dm... GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609 Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47659P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47659 [HIGH] CVE-2022-47659: gpac - GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_... GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47657P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47657 [HIGH] CVE-2022-47657: gpac - GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in functi... GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662 Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47661P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47661 [HIGH] CVE-2022-47661: gpac - GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media... GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47091P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47091 [HIGH] CVE-2022-47091: gpac - GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_tex... GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47660P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47660 [HIGH] CVE-2022-47660: gpac - GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/iso... GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-45343P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-45343 [HIGH] CVE-2022-45343: gpac - GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-afte... GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-1654P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-1654 [HIGH] CVE-2023-1654: gpac - Denial of Service in GitHub repository gpac/gpac prior to 2.4.0. Denial of Service in GitHub repository gpac/gpac prior to 2.4.0. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-31255P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31255 [HIGH] CVE-2021-31255: gpac - Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows att... Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-40568P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40568 [HIGH] CVE-2021-40568: gpac - A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4... A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40571P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40571 [HIGH] CVE-2021-40571: gpac - The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_... The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40570P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40570 [HIGH] CVE-2021-40570: gpac - The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compu... The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2019-12483P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-12483 [HIGH] CVE-2019-12483: ccextractor - An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in ... An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box. Scope: local bullseye: open
debian
CVE-2019-11221P4HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-5 (bullseye)2019
CVE-2019-11221 [HIGH] CVE-2019-11221: gpac - GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-5)
debian