Gpac · Gpac · CVE-2023-46427
**Name of the Vulnerable Software and Affected Versions**
gpac version 2.3-DEV-rev588-g7edc40fee-master
**Description**
An issue in gpac allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in the `gf dash setup period` component in `media tools/dash client.c`. This issue affects the `gf dash setup period` component, which is part of the `media tools/dash client.c` file.
**Recommendations**
For gpac version 2.3-DEV-rev588-g7edc40fee-master, consider disabling the `gf dash setup period` component in `media tools/dash client.c` as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.