CVE-2019-12483: Buffer Overflow
Published May 30, 2019
·Updated
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGFIPMPXRemoveToolNotificationListener in odf/ipmpxcode.c in libgpac.a, as demonstrated by MP4Box.
Affected Software
3 affected components
Gpac GPAC=0.7.1
Debian Debian Linux=8.0
Gpac GPAC>=0.6.1<=0.7.1
Event History
May 30, 2019
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12483?
CVE-2019-12483 is classified as having a high severity due to the potential for a heap-based buffer overflow.
2
How do I fix CVE-2019-12483?
To fix CVE-2019-12483, you should update GPAC to a version later than 0.7.1 that contains the patch for this vulnerability.
3
What systems are affected by CVE-2019-12483?
CVE-2019-12483 affects GPAC version 0.7.1 and potentially any application that utilizes this version.
4
What type of vulnerability is CVE-2019-12483?
CVE-2019-12483 is a heap-based buffer overflow vulnerability.
5
Can CVE-2019-12483 be exploited remotely?
Yes, CVE-2019-12483 can potentially be exploited remotely if an attacker can control the input to the vulnerable function.