First published: Fri Jun 29 2018(Updated: )
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gpac | 1.0.1+dfsg1-4+deb11u3 | |
Debian Linux | =8.0 | |
GPAC MP4Box | =0.7.1 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13005 has been classified as a moderate severity vulnerability due to the potential for heap-based buffer over-read.
To fix CVE-2018-13005, you should update the GPAC package to version 1.0.1+dfsg1-4+deb11u3 or later.
GPAC version 0.7.1 is affected by CVE-2018-13005.
CVE-2018-13005 poses a risk on Debian Linux 8.0 and Ubuntu Linux versions 16.04, 18.04, and 18.10.
CVE-2018-13005 is a heap-based buffer over-read vulnerability.