PT-2022-5597 · Gpac+2 · Gpac+2

Published

2018-12-19

·

Updated

2023-05-27

·

CVE-2022-3957

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GPAC (affected versions not specified)
Description The issue is related to the function svg parse preserveaspectratio() of the SVG Parser component in the GPAC multimedia platform. It is caused by incorrect clearing or freeing of resources, leading to a memory leak. This can be exploited by a remote attacker to cause a denial of service. The attack can be launched remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name 2191e66aa7df750e8ef01781b1930bea87b713bb. As a temporary workaround, consider disabling the svg parse preserveaspectratio() function until a patch is available. Restrict access to the vulnerable SVG Parser component to minimize the risk of exploitation.

Fix

Improper Resource Release

Memory Leak

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
BDU:2022-06960
CVE-2022-3957
DSA-5411-1

Affected Products

Alt Linux
Gpac
Red Os