CVE-2018-20762: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only
  • Gpac Project Gpac: up to and including 0.7.1

Published 2019-02-06. Last modified 2026-06-17.