First published: Fri Jun 29 2018(Updated: )
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gpac | 1.0.1+dfsg1-4+deb11u3 | |
Debian Linux | =8.0 | |
GPAC MP4Box | =0.7.1 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13006 has been categorized as a moderate severity vulnerability due to its potential for a heap-based buffer over-read.
To fix CVE-2018-13006, you should upgrade to GPAC version 1.0.1+dfsg1-4+deb11u3 or later.
CVE-2018-13006 affects GPAC version 0.7.1 and specific versions of Debian and Ubuntu systems.
CVE-2018-13006 is a heap-based buffer over-read vulnerability found in the MP4Box component of GPAC.
Yes, CVE-2018-13006 has been addressed in subsequent releases of the affected software.