CVE-2018-21016: Medium severity gpac mp4box vulnerability
Published Sep 16, 2019
·Updated
audiosampleentryAddBox() at isomedia/boxcodebase.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Affected Software
2 affected components
Gpac GPAC=0.7.1
Debian Debian Linux=8.0
Event History
Sep 16, 2019
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21016?
CVE-2018-21016 has a severity rating that indicates it can lead to a denial of service due to a heap-based buffer over-read and application crash.
2
How do I fix CVE-2018-21016?
To fix CVE-2018-21016, upgrade GPAC to a version beyond 0.7.1, or apply the relevant patches if available.
3
Who is affected by CVE-2018-21016?
CVE-2018-21016 affects users of GPAC version 0.7.1 and Debian Linux version 8.0.
4
What type of vulnerability is CVE-2018-21016?
CVE-2018-21016 is a denial of service vulnerability caused by improper handling of crafted media files.
5
Can CVE-2018-21016 be exploited remotely?
Yes, CVE-2018-21016 can be exploited remotely through crafted media files, impacting the affected software's stability.