CVE-2018-13007

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
29/06/2018
Last modified:
21/08/2018

Description

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (not conditional on a buffer_size_longs check).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gopro:gpmf-parser:1.1.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools