First published: Tue Sep 21 2021(Updated: )
An issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_code.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GPAC MP4Box | =0.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23266 has a severity rating that indicates it can lead to a denial of service (DOS) due to a heap-based buffer overflow.
CVE-2020-23266 affects gpac 0.8.0 by introducing a vulnerability in the OD_ReadUTF8String function that can be exploited with a crafted media file.
To fix CVE-2020-23266, it is recommended to update gpac to a version higher than 0.8.0 that addresses this vulnerability.
Yes, CVE-2020-23266 can be exploited remotely through a crafted media file that triggers the heap-based buffer overflow.
Exploiting CVE-2020-23266 can lead to denial of service conditions, making the affected application unresponsive.