7.5
CVSSv2

CVE-2018-13006

Published: 29/06/2018 Updated: 29/03/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

gpac gpac 0.7.1

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.10

Vendor Advisories

GPAC could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #902782 CVE-2018-13005 / CVE-2018-13006 Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 30 Jun 2018 20:33:02 UTC Severity: important Tags: fixed-upstream, security, up ...
Debian Bug report logs - #921969 CVE-2018-20760 CVE-2018-20761 CVE-2018-20762 CVE-2018-20763 Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 10 Feb 2019 18:51:01 UTC Severity: grave Tags: fixe ...
Debian Bug report logs - #892526 gpac: CVE-2018-7752: Stack buffer overflow in av_parsersc Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 10 Mar 2018 08:03:02 UTC Severity: grave Tags: ...