PT-2022-5597 · Gpac+2 · Gpac+2
Published
2018-12-19
·
Updated
2023-05-27
·
CVE-2022-3957
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GPAC (affected versions not specified)
Description
The issue is related to the function
svg parse preserveaspectratio() of the SVG Parser component in the GPAC multimedia platform. It is caused by incorrect clearing or freeing of resources, leading to a memory leak. This can be exploited by a remote attacker to cause a denial of service. The attack can be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch with the name 2191e66aa7df750e8ef01781b1930bea87b713bb. As a temporary workaround, consider disabling the
svg parse preserveaspectratio() function until a patch is available. Restrict access to the vulnerable SVG Parser component to minimize the risk of exploitation.Fix
Improper Resource Release
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Gpac
Red Os