#VU17700 Buffer overflow in GPAC - CVE-2018-20761

 

#VU17700 Buffer overflow in GPAC - CVE-2018-20761

Published: February 14, 2019


Vulnerability identifier: #VU17700
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2018-20761
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
GPAC
Software vendor:
GPAC

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to due to a buffer overflow condition in the gf_sm_load_init function. A remote attacker can trick the victim into executing the MP4Box command that submits malicious input, trigger memory corruption and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Remediation

Install updates from vendor's website.

External links