Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-35980

Опубликовано: 21 апр. 2021
Источник: debian
EPSS Низкий

Описание

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gpacfixed2.0.0+dfsg1-2package
gpacnot-affectedbusterpackage
gpacnot-affectedstretchpackage
ccextractorfixed0.93+ds2-1package
ccextractornot-affectedbullseyepackage
ccextractornot-affectedbusterpackage

Примечания

  • https://github.com/gpac/gpac/commit/5aba27604d957e960d8069d85ccaf868f8a7b07a (v2.0.0)

  • https://github.com/gpac/gpac/issues/1661

  • Introduced by https://github.com/gpac/gpac/commit/51dadae6c790af3f639c4d9d660658b2848b51a0

  • The vulnerability refers to the stbl member of the TrackWriter struct in isom_writer.c, which was only introduced in 51dadae6c7

EPSS

Процентиль: 33%
0.00133
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

CVSS3: 7.8
nvd
почти 5 лет назад

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

EPSS

Процентиль: 33%
0.00133
Низкий