{"id":"CVE-2018-13009","details":"An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).","modified":"2026-03-14T09:27:32.851099Z","published":"2018-06-29T14:29:00.573Z","references":[{"type":"EVIDENCE","url":"https://github.com/gopro/gpmf-parser/issues/29"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gopro/gpmf-parser","events":[{"introduced":"0"},{"last_affected":"3ee97b696ea079e9b0d666ce2165d5a86035bbb2"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.1.2"}]}}],"versions":["v1.0","v1.01","v1.1","v1.1.1","v1.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-13009.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}