CVE-2018-13006: Critical severity Debian Debian Linux vulnerability
Published Jun 29, 2018
·Updated
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/boxdump.c function hdlrdump.
Affected Software
6 affected componentsFixes available
debian/gpac
1.0.1+dfsg1-4+deb11u3
Debian Debian Linux=8.0
Gpac GPAC=0.7.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Remediation
Event History
Jun 29, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:50 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·03:18 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-13006?
CVE-2018-13006 has been categorized as a moderate severity vulnerability due to its potential for a heap-based buffer over-read.
2
How do I fix CVE-2018-13006?
To fix CVE-2018-13006, you should upgrade to GPAC version 1.0.1+dfsg1-4+deb11u3 or later.
3
Which software versions are affected by CVE-2018-13006?
CVE-2018-13006 affects GPAC version 0.7.1 and specific versions of Debian and Ubuntu systems.
4
What type of vulnerability is CVE-2018-13006?
CVE-2018-13006 is a heap-based buffer over-read vulnerability found in the MP4Box component of GPAC.
5
Is CVE-2018-13006 patched in the latest software releases?
Yes, CVE-2018-13006 has been addressed in subsequent releases of the affected software.