cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 5 of 10
CVE-2023-0866P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-0866 [HIGH] CVE-2023-0866: gpac - Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV. Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-0819P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-0819 [HIGH] CVE-2023-0819: gpac - Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV. Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-23143P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-23143 [HIGH] CVE-2023-23143: gpac - Buffer overflow vulnerability in function avc_parse_slice in file media_tools/av... Buffer overflow vulnerability in function avc_parse_slice in file media_tools/av_parsers.c. GPAC version 2.3-DEV-rev1-g4669ba229-master. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-2454P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-2454 [HIGH] CVE-2022-2454: gpac - Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV. Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-0760P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u3 (bullseye)2023
CVE-2023-0760 [HIGH] CVE-2023-0760: gpac - Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV. Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u3)
debian
CVE-2018-20761P4HIGHCVSS 7.8fixed in gpac 0.5.2-426-gc5ad4e4+dfsg5-4.1 (bullseye)2018
CVE-2018-20761 [HIGH] CVE-2018-20761: gpac - GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_... GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a. Scope: local bullseye: resolved (fixed in 0.5.2-426-gc5ad4e4+dfsg5-4.1)
debian
CVE-2021-36414P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-36414 [HIGH] CVE-2021-36414: gpac - A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via me... A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-23145P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-23145 [HIGH] CVE-2023-23145: gpac - GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak ... GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak in lsr_read_rare_full function. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47094P4HIGHCVSS 7.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47094 [HIGH] CVE-2022-47094: gpac - GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference ... GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-19750P4HIGHCVSS 7.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-19750 [HIGH] CVE-2020-19750: gpac - An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c ha... An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-23267P4HIGHCVSS 7.1fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23267 [HIGH] CVE-2020-23267: gpac - An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in i... An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2022-3957P4MEDIUMCVSS 4.3fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-3957 [MEDIUM] CVE-2022-3957: gpac - A vulnerability classified as problematic was found in GPAC. Affected by this vu... A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to
debian
CVE-2019-20208P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20208 [MEDIUM] CVE-2019-20208: ccextractor - dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-ba... dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow. Scope: local bullseye: open
debian
CVE-2018-21016P4MEDIUMCVSS 6.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2018
CVE-2018-21016 [MEDIUM] CVE-2018-21016: gpac - audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows rem... audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2018-21015P4MEDIUMCVSS 6.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2018
CVE-2018-21015 [MEDIUM] CVE-2018-21015: ccextractor - AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attacker... AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL. Scope: local bullseye: open
debian
CVE-2020-23931P4HIGHCVSS 7.1fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23931 [HIGH] CVE-2020-23931: gpac - An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_... An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-23928P4HIGHCVSS 7.1fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23928 [HIGH] CVE-2020-23928: gpac - An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_... An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-31261P4LOWCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31261 [MEDIUM] CVE-2021-31261: gpac - The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory v... The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2019-20171P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20171 [MEDIUM] CVE-2019-20171: ccextractor - An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. Th... An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c. Scope: local bullseye: open
debian
CVE-2021-40592P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40592 [MEDIUM] CVE-2021-40592: gpac - GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.... GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file. Scope: local bullseye: resolve
debian
Debian Gpac vulnerabilities | cvebase