PT-2022-18249 · Unknown+1 · Gpac Mp4Box+1

Aaardu

·

Published

2018-12-19

·

Updated

2023-05-27

·

CVE-2022-27147

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC mp4box version 1.1.0-DEV-rev1727-g8be34973d-master
Description The issue is related to a use-after-free vulnerability in the gf node get attribute by tag function. This vulnerability can lead to memory corruption and potentially allow an attacker to execute arbitrary code.
Recommendations For GPAC mp4box version 1.1.0-DEV-rev1727-g8be34973d-master, as a temporary workaround, consider disabling the gf node get attribute by tag function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
CVE-2022-27147
DSA-5411-1

Affected Products

Alt Linux
Gpac Mp4Box