CVE-2022-45283: High severity gpac mp4box vulnerability
Published Dec 5, 2022
·Updated
GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smilparsetimelist parameter at /scenegraph/svgattributes.c.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5, <=2.2.1+dfsg1-3
1.0.1+dfsg1-4+deb11u3
Gpac GPAC=2.0.0
Event History
Dec 5, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 6, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45283?
The severity of CVE-2022-45283 is classified as high due to the potential for a stack overflow.
2
How can I fix CVE-2022-45283?
To fix CVE-2022-45283, upgrade to GPAC version 2.0.1 or later which addresses the vulnerability.
3
Which versions of GPAC are affected by CVE-2022-45283?
CVE-2022-45283 affects GPAC version 2.0.0 and earlier versions.
4
Is there a workaround for CVE-2022-45283?
Currently, there is no documented workaround for CVE-2022-45283; updating to a fixed version is recommended.
5
What is the impact of exploiting CVE-2022-45283?
Exploiting CVE-2022-45283 can lead to arbitrary code execution due to the stack overflow vulnerability.