cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 6 of 10
CVE-2022-27145P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-27145 [MEDIUM] CVE-2022-27145: gpac - GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerabili... GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-31256P4LOWCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31256 [MEDIUM] CVE-2021-31256: gpac - Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows a... Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-33361P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-33361 [MEDIUM] CVE-2021-33361: gpac - Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attacke... Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-33366P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-33366 [MEDIUM] CVE-2021-33366: gpac - Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allo... Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-33364P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-33364 [MEDIUM] CVE-2021-33364: gpac - Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows at... Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-24829P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-24829 [MEDIUM] CVE-2020-24829: ccextractor - An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box... An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_section_complete in media_tools/mpegts.c that can cause a denial of service (DOS) via a crafted MP4 file. Scope: local bullseye: open
debian
CVE-2021-33363P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-33363 [MEDIUM] CVE-2021-33363: gpac - Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attacke... Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-33365P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-33365 [MEDIUM] CVE-2021-33365: gpac - Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows a... Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40562P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40562 [MEDIUM] CVE-2021-40562: gpac - A Segmentation fault caused by a floating point exception exists in Gpac through... A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40566P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40566 [MEDIUM] CVE-2021-40566: gpac - A Segmentation fault casued by heap use after free vulnerability exists in Gpac ... A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-22677P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22677 [MEDIUM] CVE-2020-22677: gpac - An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c ... An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-22678P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22678 [MEDIUM] CVE-2020-22678: gpac - An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes ... An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-22675P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22675 [MEDIUM] CVE-2020-22675: gpac - An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c h... An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-23269P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23269 [MEDIUM] CVE-2020-23269: gpac - An issue was discovered in gpac 0.8.0. The stbl_GetSampleSize function in isomed... An issue was discovered in gpac 0.8.0. The stbl_GetSampleSize function in isomedia/stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-23266P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23266 [MEDIUM] CVE-2020-23266: gpac - An issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_cod... An issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_code.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-30014P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-30014 [MEDIUM] CVE-2021-30014: ccextractor - There is a integer overflow in media_tools/av_parsers.c in the hevc_parse_slice_... There is a integer overflow in media_tools/av_parsers.c in the hevc_parse_slice_segment function in GPAC from v0.9.0-preview to 1.0.1 which results in a crash. Scope: local bullseye: open
debian
CVE-2019-20628P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20628 [MEDIUM] CVE-2019-20628: gpac - An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP... An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a Use-After-Free vulnerability in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-30019P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-30019 [MEDIUM] CVE-2021-30019: gpac - In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a craf... In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a crafted file may cause ctx->hdr.frame_size to be smaller than ctx->hdr.hdr_size, resulting in size to be a negative number and a heap overflow in the memcpy. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-30020P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-30020 [MEDIUM] CVE-2021-30020: gpac - In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.... In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which with crafted file, pps->num_tile_columns may be larger than sizeof(pps->column_width), which results in a heap overflow in the loop. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-40569P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40569 [MEDIUM] CVE-2021-40569: gpac - The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the i... The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
Debian Gpac vulnerabilities | cvebase