CVE-2022-1441 is a high-severity buffer overflow vulnerability (CVSS 7.8) affecting MP4Box, a component of GPAC-2.0.0, including its Debian packages. The flaw occurs when parsing MP4 files, where the `diST_box_read()` function attempts to write user-controlled content into a fixed-length buffer, leading to potential arbitrary code execution, data compromise, and denial of service. Exploitation requires user interaction, typically by opening a malicious MP4 file. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:gpac:gpac:2.0.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.