CVE-2020-22678: Buffer Overflow
Published Oct 12, 2021
·Updated
An issue was discovered in gpac 0.8.0. The gfmedianaluremoveemulationbytes function in avparsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
Affected Software
1 affected component
Gpac GPAC=0.8.0
Remediation
Patch Available
Event History
Oct 12, 2021
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22678?
CVE-2020-22678 is classified as a high severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2020-22678?
To fix CVE-2020-22678, you should upgrade gpac to version 0.8.1 or later, where this vulnerability has been addressed.
3
What type of vulnerability is CVE-2020-22678?
CVE-2020-22678 is a heap-based buffer overflow vulnerability located in the gf_media_nalu_remove_emulation_bytes function.
4
What software is affected by CVE-2020-22678?
CVE-2020-22678 specifically affects gpac version 0.8.0.
5
Can CVE-2020-22678 be exploited remotely?
Yes, CVE-2020-22678 can be exploited remotely via crafted input that triggers the buffer overflow.