CVE-2020-23266: Buffer Overflow
An issue was discovered in gpac 0.8.0. The ODReadUTF8String function in odfcode.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-23266?
CVE-2020-23266 has a severity rating that indicates it can lead to a denial of service (DOS) due to a heap-based buffer overflow.
How does CVE-2020-23266 affect gpac 0.8.0?
CVE-2020-23266 affects gpac 0.8.0 by introducing a vulnerability in the OD_ReadUTF8String function that can be exploited with a crafted media file.
How do I fix CVE-2020-23266?
To fix CVE-2020-23266, it is recommended to update gpac to a version higher than 0.8.0 that addresses this vulnerability.
Can CVE-2020-23266 be exploited remotely?
Yes, CVE-2020-23266 can be exploited remotely through a crafted media file that triggers the heap-based buffer overflow.
What are the consequences of exploiting CVE-2020-23266?
Exploiting CVE-2020-23266 can lead to denial of service conditions, making the affected application unresponsive.