cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 7 of 10
CVE-2019-20170P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20170 [MEDIUM] CVE-2019-20170: ccextractor - An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. Th... An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c. Scope: local bullseye: open
debian
CVE-2022-27147P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-27147 [MEDIUM] CVE-2022-27147: gpac - GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerabili... GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-41458P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-41458 [MEDIUM] CVE-2021-41458: gpac - In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:176... In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-36191P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-36191 [MEDIUM] CVE-2022-36191: gpac - A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isome... A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2024-57184P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2024
CVE-2024-57184 [MEDIUM] CVE-2024-57184: gpac - An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a... An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2023-23144P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-23144 [MEDIUM] CVE-2023-23144: gpac - Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unqu... Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012bbfb-master. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47662P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47662 [MEDIUM] CVE-2022-47662: gpac - GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due ... GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662 Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-30022P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-30022 [MEDIUM] CVE-2021-30022: gpac - There is a integer overflow in media_tools/av_parsers.c in the gf_avc_read_pps_b... There is a integer overflow in media_tools/av_parsers.c in the gf_avc_read_pps_bs_internal in GPAC from 0.5.2 to 1.0.1. pps_id may be a negative number, so it will not return. However, avc->pps only has 255 unit, so there is an overflow, which results a crash. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2019-20630P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20630 [MEDIUM] CVE-2019-20630: gpac - An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP... An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer over-read in BS_ReadByte (called from gf_bs_read_bit) in utils/bitstream.c that can cause a denial of service via a crafted MP4 file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2019-20629P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20629 [MEDIUM] CVE-2019-20629: gpac - An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP... An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer over-read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2019-20161P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20161 [MEDIUM] CVE-2019-20161: ccextractor - An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. Th... An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c. Scope: local bullseye: open
debian
CVE-2019-20162P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20162 [MEDIUM] CVE-2019-20162: ccextractor - An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. Th... An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c. Scope: local bullseye: open
debian
CVE-2021-30199P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-30199 [MEDIUM] CVE-2021-30199: gpac - In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, whe... In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-30015P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-30015 [MEDIUM] CVE-2021-30015: gpac - There is a Null Pointer Dereference in function filter_core/filter_pck.c:gf_filt... There is a Null Pointer Dereference in function filter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1. The pid comes from function av1dmx_parse_flush_sample, the ctx.opid maybe NULL. The result is a crash in gf_filter_pck_new_alloc_internal. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-40567P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40567 [MEDIUM] CVE-2021-40567: gpac - Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_siz... Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c when using mp4box, which causes a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2019-20165P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20165 [MEDIUM] CVE-2019-20165: gpac - An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. Th... An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2019-20163P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20163 [MEDIUM] CVE-2019-20163: gpac - An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. Th... An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-40565P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40565 [MEDIUM] CVE-2021-40565: gpac - A Segmentation fault caused by a null pointer dereference vulnerability exists i... A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gf_avc_parse_nalu function in av_parsers.c when using mp4box, which causes a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40563P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40563 [MEDIUM] CVE-2021-40563: gpac - A Segmentation fault exists casued by null pointer dereference exists in Gpac th... A Segmentation fault exists casued by null pointer dereference exists in Gpac through 1.0.1 via the naludmx_create_avc_decoder_config function in reframe_nalu.c when using mp4box, which causes a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40564P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40564 [MEDIUM] CVE-2021-40564: gpac - A Segmentation fault caused by null pointer dereference vulnerability eists in G... A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
Debian Gpac vulnerabilities | cvebase