VYPR
High severity7.8OSV Advisory· Published Feb 6, 2019· Updated Jun 17, 2026

CVE-2018-20762

CVE-2018-20762

Description

GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Gpac/GpacOSV2 versions
    v0.5.2, v0.6.0, v0.7.0, …+ 1 more
    • (no CPE)range: v0.5.2, v0.6.0, v0.7.0, …
    • (no CPE)range: <=0.7.1
  • cpe:2.3:a:gpac_project:gpac:*:*:*:*:*:*:*:*
    Range: <=0.7.1
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • Gpac/MP4Boxllm-fuzzy
    Range: <=0.7.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.