CVE-2022-47658

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
05/01/2023
Last modified:
10/04/2025

Description

GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* 2.2.0 (excluding)