Gpac · Gpac · CVE-2023-48039
**Name of the Vulnerable Software and Affected Versions**
GPAC versions 2.3-DEV-rev617-g671976fcc-master
**Description**
The issue is related to a memory leak in the `gf mpd parse string` function, located in `media tools/mpd.c:75`, due to the lack of memory release after its effective term of service. Exploitation of this issue may allow a remote attacker to cause a denial of service.
**Recommendations**
For GPAC version 2.3-DEV-rev617-g671976fcc-master, consider disabling the `gf mpd parse string` function as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.