6.8
CVSSv2

CVE-2018-20760

Published: 06/02/2019 Updated: 15/04/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In GPAC 0.7.1 and previous versions, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gpac gpac

debian debian linux 8.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

GPAC could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #902782 CVE-2018-13005 / CVE-2018-13006 Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 30 Jun 2018 20:33:02 UTC Severity: important Tags: fixed-upstream, security, up ...
Debian Bug report logs - #921969 CVE-2018-20760 CVE-2018-20761 CVE-2018-20762 CVE-2018-20763 Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 10 Feb 2019 18:51:01 UTC Severity: grave Tags: fixe ...
Debian Bug report logs - #892526 gpac: CVE-2018-7752: Stack buffer overflow in av_parsersc Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 10 Mar 2018 08:03:02 UTC Severity: grave Tags: ...