CVE-2019-20168: Use After Free
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gfisomboxdumpex() in isomedia/boxfuncs.c.
Affected Software
2 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20168?
CVE-2019-20168 has been classified as a high severity vulnerability due to the potential for exploitation through a use-after-free condition.
2
How do I fix CVE-2019-20168?
To fix CVE-2019-20168, upgrade GPAC to version 0.9.0 or later, which contains the patch for the vulnerability.
3
Which versions of GPAC are affected by CVE-2019-20168?
CVE-2019-20168 affects GPAC versions 0.8.0 and 0.9.0-development-20191109.
4
What type of vulnerability is CVE-2019-20168?
CVE-2019-20168 is classified as a use-after-free vulnerability, which can lead to memory corruption.
5
Can CVE-2019-20168 lead to remote code execution?
Yes, CVE-2019-20168 can potentially be exploited to execute arbitrary code remotely due to its use-after-free nature.