CVE-2020-35980: Use After Free
Published Apr 21, 2021
·Updated
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gfisomboxdel() in isomedia/boxfuncs.c.
Affected Software
4 affected componentsFixes available
debian/ccextractor
0.87+ds1-10.88+ds1-10.94+ds1-2
debian/gpac
0.5.2-426-gc5ad4e4+dfsg5-51.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=0.8.0
Gpac GPAC=1.0.1
Remediation
Event History
Apr 21, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35980?
CVE-2020-35980 is classified as a high severity vulnerability due to its potential to allow exploitation through a use-after-free condition.
2
How do I fix CVE-2020-35980?
To fix CVE-2020-35980, update to GPAC version 0.8.1 or later, or 1.0.2 or later.
3
What impact does CVE-2020-35980 have on affected software?
CVE-2020-35980 can lead to application crashes or execution of arbitrary code, affecting the stability and security of the software.
4
Which versions of GPAC are affected by CVE-2020-35980?
GPAC versions 0.8.0 and 1.0.1 are affected by CVE-2020-35980 due to the use-after-free issue.
5
Is CVE-2020-35980 exploitable remotely?
Yes, CVE-2020-35980 is considered remotely exploitable if a vulnerable version of GPAC is being used in an accessible environment.