CVE-2023-4682

Source
https://cve.org/CVERecord?id=CVE-2023-4682
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4682.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4682
Downstream
Published
2023-08-31T15:54:23.711Z
Modified
2025-12-05T00:09:39.354959Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Heap-based Buffer Overflow in gpac/gpac
Details

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

Database specific
{
    "cwe_ids": [
        "CWE-122"
    ],
    "cna_assigner": "@huntrdev",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4682.json"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.5.2
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.8.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v1.0.1
v2.*
v2.0.0
v2.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4682.json"
vanir_signatures
[
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/b1042c3eefca87c4bc32afb404ed6518d693e5be",
        "digest": {
            "function_hash": "175356884204505057408484878761826362189",
            "length": 1527.0
        },
        "id": "CVE-2023-4682-75111b30",
        "deprecated": false,
        "target": {
            "file": "src/media_tools/avilib.c",
            "function": "AVI_read_audio"
        }
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/b1042c3eefca87c4bc32afb404ed6518d693e5be",
        "digest": {
            "function_hash": "7857590004244116306279665265227823579",
            "length": 783.0
        },
        "id": "CVE-2023-4682-9b2c07f3",
        "deprecated": false,
        "target": {
            "file": "src/media_tools/avilib.c",
            "function": "AVI_read_frame"
        }
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/b1042c3eefca87c4bc32afb404ed6518d693e5be",
        "digest": {
            "line_hashes": [
                "197199226081372040039200224818249718197",
                "53820444998232757765679602121972680610",
                "252634007019762678122784395286555320978",
                "289225831808584179533879619789885761678",
                "333559792569365315895464881095709107464",
                "253458318418898890634013939916597013622",
                "64905399315484069938009329975098855603",
                "99188170747984495465011322403238179022",
                "228164518531352378260677971838238891392",
                "88761271832012926061555890012840734986",
                "83425705985582482281867687422840355544",
                "213888059613953768616215646224649951775",
                "211938840273006099908387320003029008073",
                "129374499337564337097126252817923788221",
                "39472042380934352995494174969347697607",
                "181622113545647317330546963679555845882"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2023-4682-b3d87028",
        "deprecated": false,
        "target": {
            "file": "src/media_tools/avilib.c"
        }
    }
]