CVE-2020-19750: High severity gpac mp4box vulnerability
Published Sep 7, 2021
·Updated
An issue was discovered in gpac 0.8.0. The strdup function in boxcodebase.c has a heap-based buffer over-read.
Affected Software
1 affected component
Gpac GPAC=0.8.0
Remediation
Patch Available
Event History
Sep 7, 2021
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19750?
CVE-2020-19750 has been classified with a moderate severity level due to its potential to cause a heap-based buffer over-read.
2
How do I fix CVE-2020-19750?
To fix CVE-2020-19750, update to a patched version of GPAC that addresses the buffer over-read vulnerability.
3
What software is affected by CVE-2020-19750?
The only affected software version is GPAC version 0.8.0.
4
What impact does CVE-2020-19750 have on my system?
CVE-2020-19750 may lead to memory corruption or information disclosure due to the heap-based buffer over-read.
5
Can CVE-2020-19750 be exploited remotely?
Yes, CVE-2020-19750 may be exploited remotely if an attacker can provide specially crafted input to the vulnerable GPAC application.