#VU17699 Out-of-bounds write in GPAC - CVE-2018-20760
Published: February 14, 2019
GPAC
GPAC
Description
The vulnerability exists due to due to improper handling of a certain -1 return value. A remote attacker can trick the victim into executing the MP4Box command on a SubRip Subtitle (SRT) file that submits malicious input, trigger an out-of-bounds write condition in the gf_text_get_utf8_line function and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.