CVE-2019-20160: Buffer Overflow
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1parsetilegroup() in mediatools/avparsers.c.
Affected Software
2 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:56 PM
Data Sourced
via MITRE·11:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20160?
CVE-2019-20160 has a high severity due to the potential for remote code execution through a stack-based buffer overflow.
2
How do I fix CVE-2019-20160?
To fix CVE-2019-20160, update GPAC to a version later than 0.9.0 that addresses this vulnerability.
3
What versions of GPAC are affected by CVE-2019-20160?
CVE-2019-20160 affects GPAC versions 0.8.0 and 0.9.0-development-20191109.
4
Can CVE-2019-20160 be exploited remotely?
Yes, CVE-2019-20160 can potentially be exploited remotely if the vulnerable GPAC software is deployed.
5
Is there a workaround for CVE-2019-20160?
As of now, the recommended solution for CVE-2019-20160 is to upgrade to a patched version of GPAC.