Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 8 Jessie: DLA-2072-1 Critical: gpac Denial Of Service Threats

debian lts
Calendar Grey January 20, 2020
Dist Debian Esm H88
Essential security patch released for gpac, tackling various vulnerabilities and CVEs in Debian 8. Update strongly urged for optimal stability.
Multiple issues were found in gpac, a multimedia framework featuring the MP4Box muxer

Summary

AVC_DuplicateConfig() at isomedia/avc_ext.c allows remote
attackers to cause a denial of service (NULL pointer dereference
and application crash) via a crafted file.

CVE-2018-21016

audio_sample_entry_AddBox() at isomedia/box_code_base.c allows
remote attackers to cause a denial of service (heap-based buffer
over-read and application crash) via a crafted file.

CVE-2019-13618

isomedia/isom_read.c in libgpac.a has a heap-based buffer
over-read, as demonstrated by a crash in gf_m2ts_sync in
media_tools/mpegts.c.

CVE-2019-20161

heap-based buffer overflow in the function
ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

CVE-2019-20162

heap-based buffer overflow in the function gf_isom_box_parse_ex()
in isomedia/box_funcs.c.

CVE-2019-20163

NULL pointer dereference in the function gf_odf_avc_cfg_write_bs()
in odf/descriptors.c.

CVE-2019-20165

NULL pointer dereference in the function ilst_item_Read() in
isomedia/box_code_apple.c.

CVE-2019-20170

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: gpac
Version: 0.5.0+svn5324~dfsg1-1+deb8u5
CVE ID: CVE-2018-21015 CVE-2018-21016 CVE-2019-13618
Debian Bug: 940882 932242

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here