SB20200405162 - Use-after-free in GPAC



SB20200405162 - Use-after-free in GPAC

Published: April 5, 2020 Updated: August 8, 2020

Security Bulletin ID SB20200405162
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use-after-free (CVE-ID: CVE-2020-11558)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes.


Remediation

Install update from vendor's website.