CVE-2018-13005: Critical severity Debian Debian Linux vulnerability
Published Jun 29, 2018
·Updated
An issue was discovered in MP4Box in GPAC 0.7.1. The function urnRead in isomedia/boxcodebase.c has a heap-based buffer over-read.
Affected Software
6 affected componentsFixes available
debian/gpac
1.0.1+dfsg1-4+deb11u3
Debian Debian Linux=8.0
Gpac GPAC=0.7.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Event History
Jun 29, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:50 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·03:18 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-13005?
CVE-2018-13005 has been classified as a moderate severity vulnerability due to the potential for heap-based buffer over-read.
2
How do I fix CVE-2018-13005?
To fix CVE-2018-13005, you should update the GPAC package to version 1.0.1+dfsg1-4+deb11u3 or later.
3
Which versions of GPAC are affected by CVE-2018-13005?
GPAC version 0.7.1 is affected by CVE-2018-13005.
4
On which operating systems does CVE-2018-13005 pose a risk?
CVE-2018-13005 poses a risk on Debian Linux 8.0 and Ubuntu Linux versions 16.04, 18.04, and 18.10.
5
What type of vulnerability is CVE-2018-13005?
CVE-2018-13005 is a heap-based buffer over-read vulnerability.