CVE-2022-30976: High severity gpac mp4box vulnerability
Published May 18, 2022
·Updated
GPAC 2.0.0 misuses a certain Unicode utf8wcslen (renamed gfutf8wcslen) function in utils/utf.c, resulting in a heap-based buffer over-read, as demonstrated by MP4Box.
Affected Software
1 affected component
Gpac GPAC=2.0.0
Remediation
Patch Available
Event History
May 18, 2022
CVE Published
via MITRE·05:20 AM
Data Sourced
via MITRE·05:20 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-30976?
CVE-2022-30976 is categorized as a medium-severity vulnerability due to the heap-based buffer over-read that it induces.
2
How do I fix CVE-2022-30976?
To fix CVE-2022-30976, upgrade GPAC to version 2.0.1 or later, which contains the necessary patches.
3
What systems are affected by CVE-2022-30976?
CVE-2022-30976 specifically affects GPAC version 2.0.0.
4
What type of vulnerability is CVE-2022-30976?
CVE-2022-30976 is a heap-based buffer over-read vulnerability which can lead to potential information disclosure.
5
Is CVE-2022-30976 exploitable in the wild?
There have been no confirmed reports of CVE-2022-30976 being actively exploited in the wild.