CVE-2022-4202

Source
https://cve.org/CVERecord?id=CVE-2022-4202
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-4202.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-4202
Downstream
Published
2022-11-29T00:00:00Z
Modified
2026-05-15T11:53:28.990667550Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
GPAC lsr_dec.c lsr_translate_coords integer overflow
Details

A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsrtranslatecoords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is b3d821c4ae9ba62b3a194d9dcb5e99f17bd56908. It is recommended to apply a patch to fix this issue. VDB-214518 is the identifier assigned to this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-189"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "last_affected": "2.1-DEV-rev490-g68064e101-master"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4202.json",
    "cna_assigner": "VulDB"
}
References

Affected packages