CVE-2018-13007: Gopro Gpmf-Parser

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (not conditional on a buffer_size_longs check).

Affected products

  • Gopro Gpmf-Parser: version 1.1.2 only

Published 2018-06-29. Last modified 2026-06-17.