cbcvebase.

Debian Gpac vulnerabilities

200 known vulnerabilities affecting debian/gpac.

Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5

Vulnerabilities

Page 8 of 10
CVE-2021-45760P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45760 [MEDIUM] CVE-2021-45760: gpac - GPAC v1.1.0 was discovered to contain an invalid memory address dereference via ... GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_list_last(). This vulnerability allows attackers to cause a Denial of Service (DoS). Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-6630P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-6630 [MEDIUM] CVE-2020-6630: ccextractor - An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereferen... An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c. Scope: local bullseye: open
debian
CVE-2020-6631P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-6631 [MEDIUM] CVE-2020-6631: ccextractor - An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereferen... An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in media_tools/m2ts_mux.c. Scope: local bullseye: open
debian
CVE-2021-40559P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40559 [MEDIUM] CVE-2021-40559: gpac - A null pointer deference vulnerability exists in gpac through 1.0.1 via the nalu... A null pointer deference vulnerability exists in gpac through 1.0.1 via the naludmx_parse_nal_avc function in reframe_nalu, which allows a denail of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-24574P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-24574 [MEDIUM] CVE-2022-24574: gpac - GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ... GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra (). Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45762P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45762 [MEDIUM] CVE-2021-45762: gpac - GPAC v1.1.0 was discovered to contain an invalid memory address dereference via ... GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS). Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46047P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46047 [MEDIUM] CVE-2021-46047: gpac - A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the gf_hinter_final... A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the gf_hinter_finalize function. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46041P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46041 [MEDIUM] CVE-2021-46041: gpac - A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new fun... A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45297P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45297 [MEDIUM] CVE-2021-45297: gpac - An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size. An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45831P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45831 [MEDIUM] CVE-2021-45831: gpac - A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __st... A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-29537P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-29537 [MEDIUM] CVE-2022-29537: gpac - gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based bu... gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-19481P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-19481 [MEDIUM] CVE-2020-19481: gpac - An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It cont... An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2019-12481P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-12481 [MEDIUM] CVE-2019-12481: ccextractor - An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in th... An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box. Scope: local bullseye: open
debian
CVE-2021-31258P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31258 [MEDIUM] CVE-2021-31258: ccextractor - The gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to cause ... The gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. Scope: local bullseye: open
debian
CVE-2021-40572P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40572 [MEDIUM] CVE-2021-40572: gpac - The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize fun... The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40576P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40576 [MEDIUM] CVE-2021-40576: gpac - The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in ... The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40575P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40575 [MEDIUM] CVE-2021-40575: gpac - The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in ... The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fix for CVE-2021-40566. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-1222P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-1222 [MEDIUM] CVE-2022-1222: gpac - Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV. Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-1035P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-1035 [MEDIUM] CVE-2022-1035: gpac - Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to... Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-19488P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-19488 [MEDIUM] CVE-2020-19488: gpac - An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows att... An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read. Scope: local bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian