CVE-2022-29537: Medium severity gpac mp4box vulnerability
Published Apr 20, 2022
·Updated
gprtpbuilderdohevc in ietf/rtppckmpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5
1.0.1+dfsg1-4+deb11u32.2.1+dfsg1-3
Gpac GPAC=2.0.0
Event History
Apr 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29537?
CVE-2022-29537 is classified as a medium-severity vulnerability due to the potential for a heap-based buffer over-read.
2
How do I fix CVE-2022-29537?
To fix CVE-2022-29537, upgrade to GPAC versions 1.0.1+dfsg1-4+deb11u3 or 2.2.1+dfsg1-3.
3
What software is affected by CVE-2022-29537?
CVE-2022-29537 affects GPAC version 2.0.0 and earlier versions.
4
What type of vulnerability is CVE-2022-29537?
CVE-2022-29537 is identified as a heap-based buffer over-read in the GPAC library.
5
Can CVE-2022-29537 be exploited remotely?
Yes, CVE-2022-29537 can potentially be exploited remotely through malicious MP4 files.