First published: Thu May 30 2019(Updated: )
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GPAC MP4Box | =0.7.1 | |
Debian Linux | =8.0 | |
GPAC MP4Box | >=0.6.1<=0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12483 is classified as having a high severity due to the potential for a heap-based buffer overflow.
To fix CVE-2019-12483, you should update GPAC to a version later than 0.7.1 that contains the patch for this vulnerability.
CVE-2019-12483 affects GPAC version 0.7.1 and potentially any application that utilizes this version.
CVE-2019-12483 is a heap-based buffer overflow vulnerability.
Yes, CVE-2019-12483 can potentially be exploited remotely if an attacker can control the input to the vulnerable function.