CVE-2019-20161: Buffer Overflow
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGFIPMPXWatermarkingInit() in odf/ipmpxcode.c.
Affected Software
3 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Debian Debian Linux=8.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:56 PM
Data Sourced
via MITRE·11:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20161?
CVE-2019-20161 is classified as a critical vulnerability due to its potential for causing heap-based buffer overflow.
2
How do I fix CVE-2019-20161?
To mitigate CVE-2019-20161, upgrade GPAC to a version later than 0.9.0.
3
Which versions of GPAC are affected by CVE-2019-20161?
CVE-2019-20161 affects GPAC versions 0.8.0 and 0.9.0-development-20191109.
4
What impact does CVE-2019-20161 have on software security?
CVE-2019-20161 can lead to arbitrary code execution due to a heap-based buffer overflow.
5
Is CVE-2019-20161 present in Debian Linux?
Yes, CVE-2019-20161 is present in Debian Linux 8.0 when using the affected versions of GPAC.