PT-2023-1156 · Gpac+2 · Gpac+2

Published

2018-12-19

·

Updated

2023-01-25

·

CVE-2023-0358

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gpac/gpac versions prior to 2.3.0-DEV
Description The issue is related to a Use After Free condition in the gpac/gpac multimedia platform, specifically concerning the gf odf vvc cfg read bs() function. This condition involves the use of memory after it has been freed, which can lead to arbitrary code execution or denial of service.
Recommendations For versions prior to 2.3.0-DEV, update to version 2.3.0-DEV or later to resolve the issue. As a temporary workaround, consider disabling the gf odf vvc cfg read bs() function until a patch is available.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
BDU:2023-00370
CVE-2023-0358

Affected Products

Alt Linux
Debian
Gpac