First published: Thu Jan 05 2023(Updated: )
GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GPAC MP4Box | <2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-47656 is high with a severity value of 7.8.
GPAC versions up to and excluding 2.2.0 are affected by CVE-2022-47656.
There is currently no fix available for the Buffer Overflow vulnerability in GPAC MP4box. It is recommended to monitor for updates from the vendor and apply patches or upgrades as they become available.
You can find more information about CVE-2022-47656 on the GitHub issue page at https://github.com/gpac/gpac/issues/2353.
CVE-2022-47656 is associated with CWE categories 119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and 120 (Buffer Copy without Checking Size of Input).