VDB

CVE-2020-11558

CVE-2020-11558 PUBLISHED

An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes.

EPSS 0.42% · 62.2th percentile

Risk Scores

EPSS Score
0.42%
62.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSccextractor0, *
Ubuntu:Pro:18.04:LTSgpac0.5.2-426-gc5ad4e4+dfsg5-3, 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1, 0.5.2-426-gc5ad4e4+dfsg5-3ubuntu0.1+esm1
Ubuntu:Pro:16.04:LTSgpac*, 0, 0.5.2-426-gc5ad4e4+dfsg5-1build1
Ubuntu:Pro:14.04:LTSgpac0.5.0+svn4288~dfsg1-4ubuntu1, 0.5.0+svn4288~dfsg1-4, 0.5.0+svn4288~dfsg1-4ubuntu1+esm2
Ubuntu:Pro:20.04:LTSgpac0, 0.5.2-426-gc5ad4e4+dfsg5-4ubuntu1, 0.5.2-426-gc5ad4e4+dfsg5-5
Ubuntu:24.04:LTSccextractor*, 0.94+ds1-3build2, 0.94+ds1-3
Ubuntu:22.04:LTSccextractor*, 0.93+ds2-2, 0.93+ds2-1ubuntu1

Timeline

  • Apr 5, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›