CVE-2020-35979: Buffer Overflow
Published Apr 21, 2021
·Updated
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gprtpbuilderdoavc() in ietf/rtppckmpeg4.c.
Affected Software
2 affected components
Gpac GPAC=0.8.0
Gpac GPAC=1.0.1
Remediation
Event History
Apr 21, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35979?
CVE-2020-35979 has a critical severity rating due to its potential for exploitation through heap-based buffer overflow.
2
How do I fix CVE-2020-35979?
To mitigate CVE-2020-35979, users should upgrade to the latest version of GPAC that addresses the vulnerability.
3
What software versions are affected by CVE-2020-35979?
CVE-2020-35979 specifically affects GPAC versions 0.8.0 and 1.0.1.
4
What is the nature of the vulnerability in CVE-2020-35979?
CVE-2020-35979 is a heap-based buffer overflow vulnerability found in the function gp_rtp_builder_do_avc() within GPAC.
5
Can CVE-2020-35979 be exploited remotely?
Yes, CVE-2020-35979 can potentially be exploited remotely, making it a significant security concern.