CVE-2019-20169: Use After Free
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trakRead() in isomedia/boxcodebase.c.
Affected Software
2 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20169?
CVE-2019-20169 is classified as a medium severity vulnerability due to the potential use-after-free issue that can lead to application crashes or arbitrary code execution.
2
How do I fix CVE-2019-20169?
To fix CVE-2019-20169, update to a patched version of GPAC that addresses the use-after-free vulnerability.
3
Which versions of GPAC are affected by CVE-2019-20169?
CVE-2019-20169 affects GPAC versions 0.8.0 and 0.9.0-development-20191109.
4
What kind of vulnerability is CVE-2019-20169?
CVE-2019-20169 is a use-after-free vulnerability found in the trak_Read() function in GPAC.
5
Where can I find more information about CVE-2019-20169?
For more information about CVE-2019-20169, refer to the issue report on the official GPAC GitHub repository.