CVE-2019-20170: Medium severity gpac mp4box vulnerability
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GFIPMPXAUTHDelete() in odf/ipmpxcode.c.
Affected Software
3 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Debian Debian Linux=8.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20170?
The severity of CVE-2019-20170 is classified as medium due to the potential for denial of service risks.
2
How do I fix CVE-2019-20170?
To fix CVE-2019-20170, update GPAC to version 0.9.1 or later.
3
What systems are affected by CVE-2019-20170?
CVE-2019-20170 affects GPAC versions 0.8.0 and 0.9.0, as well as Debian 8.0.
4
What type of vulnerability is CVE-2019-20170?
CVE-2019-20170 is categorized as an invalid pointer dereference vulnerability.
5
What impact does CVE-2019-20170 have?
CVE-2019-20170 can cause application crashes and potential denial of service.