9.8
CVSSv3

CVE-2022-36190

Published: 17/08/2022 Updated: 27/05/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gpac gpac

Vendor Advisories

Debian Bug report logs - #1019595 gpac: CVE-2022-38530 CVE-2022-36186 CVE-2022-36190 CVE-2022-36191 Package: src:gpac; Maintainer for src:gpac is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 12 Sep 2022 20:39:01 UTC Severity: important ...
Multiple issues were found in GPAC multimedia framework, which could result in denial of service or potentially the execution of arbitrary code For the stable distribution (bullseye), these problems have been fixed in version 101+dfsg1-4+deb11u2 We recommend that you upgrade your gpac packages For the detailed security status of gpac please re ...