#VU17702 Out-of-bounds write in GPAC - CVE-2018-20763
Published: February 14, 2019
GPAC
GPAC
Description
The vulnerability exists due to due to improper bounds checks on the szLineConv parameter in the gf_text_get_utf8_lin function. A remote attacker can trick the victim into executing the MP4Box command that submits malicious input, trigger an out-of-bounds write and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.