CVE-2022-30976

HIGH

GPAC 2.0.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

GPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-based buffer over-read, as demonstrated by MP4Box.

References (3)

Core 3

Scores

CVSS v3 7.1
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
gpac/gpac 2.0.0
Published May 18, 2022
Tracked Since Feb 18, 2026