CVE-2022-1441
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.
MP4Box es un componente de GPAC-2.0.0, que es un paquete de terceros ampliamente usado en RPM Fusion. Cuando MP4Box intenta analizar un archivo MP4, llama a la función "diST_box_read()" para leer del vídeo. En esta función, es asignado un buffer "str" con longitud fija. Sin embargo, el contenido leído desde "bs" es controlable por el usuario, así como la longitud, lo que causa un desbordamiento del buffer
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-22 CVE Reserved
- 2022-04-25 CVE Published
- 2024-07-17 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-125: Out-of-bounds Read
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/gpac/gpac/issues/2175 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/gpac/gpac/commit/3dbe11b37d65c8472faf0654410068e5500b3adb | 2023-06-27 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2023/dsa-5411 | 2023-06-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gpac Search vendor "Gpac" | Gpac Search vendor "Gpac" for product "Gpac" | 2.0.0 Search vendor "Gpac" for product "Gpac" and version "2.0.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|