CVE-2018-13006 is a critical heap-based buffer over-read vulnerability in the hdlr_dump function of MP4Box in GPAC 0.7.1, affecting various Canonical and Debian Linux distributions running GPAC. With a CVSS score of 9.8, it allows unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts over the network with low attack complexity. Although there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness despite a lack of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
0.7.1CPE matchmatch criteria | cpe:2.3:a:gpac:gpac:0.7.1:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.