Information on source package gpac

Available versions

ReleaseVersion
stretch0.5.2-426-gc5ad4e4+dfsg5-3+deb9u1
buster0.5.2-426-gc5ad4e4+dfsg5-5
bullseye1.0.1+dfsg1-4+deb11u1
bookworm1.0.1+dfsg1-5
sid1.0.1+dfsg1-5

Open issues

BugstretchbusterbullseyebookwormsidDescription
CVE-2021-41459fixedfixedvulnerablevulnerablevulnerableThere is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_n ...
CVE-2021-41457fixedfixedvulnerablevulnerablevulnerableThere is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nh ...
CVE-2021-41456fixedfixedvulnerablevulnerablevulnerableThere is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_n ...
CVE-2021-36584vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableAn issue was discovered in GPAC 1.0.1. There is a heap-based buffer ov ...
CVE-2021-33362vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableStack buffer overflow in the hevc_parse_vps_extension function in MP4B ...
CVE-2021-32440vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableThe Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to ca ...
CVE-2021-32439vulnerable (no DSA, postponed)vulnerablevulnerablevulnerablevulnerableBuffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0. ...
CVE-2021-32438fixedfixedvulnerable (no DSA, ignored)vulnerablevulnerableThe gf_media_export_filters function in GPAC 1.0.1 allows attackers to ...
CVE-2021-32437vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableThe gf_hinter_finalize function in GPAC 1.0.1 allows attackers to caus ...
CVE-2021-32271vulnerablevulnerablefixedfixedfixedAn issue was discovered in gpac through 20200801. A stack-buffer-overf ...
CVE-2021-32268vulnerablevulnerablefixedfixedfixedBuffer overflow vulnerability in function gf_fprintf in os_file.c in g ...
CVE-2021-32139vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableThe gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to c ...
CVE-2021-32138vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableThe DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a d ...
CVE-2021-32137vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableHeap buffer overflow in the URL_GetProtocolType function in MP4Box in ...
CVE-2021-32136vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableHeap buffer overflow in the print_udta function in MP4Box in GPAC 1.0. ...
CVE-2021-32135fixedfixedvulnerable (no DSA, ignored)vulnerablevulnerableThe trak_box_size function in GPAC 1.0.1 allows attackers to cause a d ...
CVE-2021-32134vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerablevulnerableThe gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause ...
CVE-2021-32132fixedfixedvulnerable (no DSA, ignored)vulnerablevulnerableThe abst_box_size function in GPAC 1.0.1 allows attackers to cause a d ...
CVE-2021-31260vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedThe MergeTrack function in GPAC 1.0.1 allows attackers to cause a deni ...
CVE-2021-31258vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedThe gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers ...
CVE-2021-31257vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedThe HintFile function in GPAC 1.0.1 allows attackers to cause a denial ...
CVE-2021-30014vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedThere is a integer overflow in media_tools/av_parsers.c in the hevc_pa ...
CVE-2021-28300vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedNULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrac ...
CVE-2021-21852fixedfixedvulnerablefixedfixedMultiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2020-35982vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an i ...
CVE-2020-35981vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an i ...
CVE-2020-35980vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a us ...
CVE-2020-35979vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap ...
CVE-2020-24829vulnerablevulnerablefixedfixedfixedAn issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It ...
CVE-2020-23269vulnerablevulnerablefixedfixedfixedAn issue was discovered in gpac 0.8.0. The stbl_GetSampleSize function ...
CVE-2020-23267vulnerablevulnerablefixedfixedfixedAn issue was discovered in gpac 0.8.0. The gf_hinter_track_process fun ...
CVE-2020-23266vulnerablevulnerablefixedfixedfixedAn issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function ...
CVE-2020-22678vulnerablevulnerable (no DSA, ignored)fixedfixedfixedAn issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulat ...
CVE-2020-22677vulnerablevulnerable (no DSA, ignored)fixedfixedfixedAn issue was discovered in gpac 0.8.0. The dump_data_hex function in b ...
CVE-2020-22675vulnerablevulnerable (no DSA, ignored)fixedfixedfixedAn issue was discovered in gpac 0.8.0. The GetGhostNum function in stb ...
CVE-2020-22674fixedvulnerable (no DSA, ignored)fixedfixedfixedAn issue was discovered in gpac 0.8.0. An invalid memory dereference e ...
CVE-2020-19751vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool functi ...
CVE-2020-19750vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in gpac 0.8.0. The strdup function in box_code ...
CVE-2020-19488vulnerablevulnerablefixedfixedfixedAn issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, ...
CVE-2020-19481vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)fixedfixedfixedAn issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Bo ...
CVE-2020-11558vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by ...
CVE-2020-6631vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0. There is a NULL pointer ...
CVE-2020-6630vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0. There is a NULL pointer ...
CVE-2019-20632vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstr ...
CVE-2019-20631vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstr ...
CVE-2019-20630vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstr ...
CVE-2019-20629vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstr ...
CVE-2019-20628vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstr ...
CVE-2019-20208vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixeddimC_Read in isomedia/box_code_3gpp.c in GPAC 0.8.0 has a stack-based ...
CVE-2019-20171vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20170vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20165vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20163vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20162vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20161vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-13618vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedIn GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-bas ...
CVE-2019-12483vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC 0.7.1. There is a heap-based buffer ov ...
CVE-2019-12482vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC 0.7.1. There is a NULL pointer derefer ...
CVE-2019-12481vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAn issue was discovered in GPAC 0.7.1. There is a NULL pointer derefer ...
CVE-2019-11222vulnerable (no DSA)fixedfixedfixedfixedgf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overfl ...
CVE-2019-11221vulnerable (no DSA)fixedfixedfixedfixedGPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media ...
CVE-2018-21016vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedaudio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 ...
CVE-2018-21015vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedAVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remot ...

Open unimportant issues

BugstretchbusterbullseyebookwormsidDescription
CVE-2021-33366fixedfixedvulnerablevulnerablevulnerableMemory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC ...
CVE-2021-33365vulnerablevulnerablevulnerablevulnerablevulnerableMemory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0. ...
CVE-2021-33364fixedfixedvulnerablevulnerablevulnerableMemory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 ...
CVE-2021-33363fixedfixedvulnerablevulnerablevulnerableMemory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allo ...
CVE-2021-33361fixedfixedvulnerablevulnerablevulnerableMemory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allo ...
CVE-2021-31261vulnerablevulnerablefixedfixedfixedThe gf_hinter_track_new function in GPAC 1.0.1 allows attackers to rea ...
CVE-2021-31256vulnerablevulnerablefixedfixedfixedMemory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0. ...
CVE-2020-22679vulnerablevulnerablefixedfixedfixedMemory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 a ...
CVE-2020-22673vulnerablevulnerablefixedfixedfixedMemory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows ...

Resolved issues

BugDescription
CVE-2021-32270An issue was discovered in gpac through 20200801. A NULL pointer deref ...
CVE-2021-32269An issue was discovered in gpac through 20200801. A NULL pointer deref ...
CVE-2021-31262The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cau ...
CVE-2021-31259The gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allo ...
CVE-2021-31255Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 ...
CVE-2021-31254Buffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 ...
CVE-2021-30199In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Derefe ...
CVE-2021-30022There is a integer overflow in media_tools/av_parsers.c in the gf_avc_ ...
CVE-2021-30020In the function gf_hevc_read_pps_bs_internal function in media_tools/a ...
CVE-2021-30019In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0 ...
CVE-2021-30015There is a Null Pointer Dereference in function filter_core/filter_pck ...
CVE-2021-29279There is a integer overflow in function filter_core/filter_props.c:gf_ ...
CVE-2021-21862Multiple exploitable integer truncation vulnerabilities exist within t ...
CVE-2021-21861An exploitable integer truncation vulnerability exists within the MPEG ...
CVE-2021-21860An exploitable integer truncation vulnerability exists within the MPEG ...
CVE-2021-21859An exploitable integer truncation vulnerability exists within the MPEG ...
CVE-2021-21858Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21857Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21856Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21855Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21854Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21853Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21851Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21850An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21849An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21848An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21847Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21846Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21845Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21844Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21843Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21842An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21841An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21840An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21839Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21838Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21837Multiple exploitable integer overflow vulnerabilities exist within the ...
CVE-2021-21836An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21835An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2021-21834An exploitable integer overflow vulnerability exists within the MPEG-4 ...
CVE-2020-23932An issue was discovered in gpac before 1.0.1. A NULL pointer dereferen ...
CVE-2020-23931An issue was discovered in gpac before 1.0.1. The abst_box_read functi ...
CVE-2020-23930An issue was discovered in gpac through 20200801. A NULL pointer deref ...
CVE-2020-23928An issue was discovered in gpac before 1.0.1. The abst_box_read functi ...
CVE-2020-22352The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attacke ...
CVE-2019-20169An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20168An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20167An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20166An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20164An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20160An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2019-20159An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20 ...
CVE-2018-1000100GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulne ...
CVE-2018-21017GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c. ...
CVE-2018-20763In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_i ...
CVE-2018-20762GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in ...
CVE-2018-20761GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in ...
CVE-2018-20760In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_i ...
CVE-2018-13006An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based ...
CVE-2018-13005An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read ...
CVE-2018-7752GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps ...

Security announcements

DSA / DLADescription
DSA-4966-1gpac - security update
DLA-2072-1gpac - security update
DLA-1841-1gpac - security update
DLA-1765-1gpac - security update
DLA-1693-1gpac - security update
DLA-1432-1gpac - security update

Search for package or bug name: Reporting problems