PT-2023-18855 · Gpac · Gpac

Published

2023-01-20

·

Updated

2023-05-27

·

CVE-2023-23143

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPAC version 2.3-DEV-rev1-g4669ba229-master
Description A buffer overflow issue exists in the avc parse slice function located in the media tools/av parsers.c file. This issue can be exploited, but details about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited are not provided. The avc parse slice function is vulnerable, but specific technical details about exploitation, such as API endpoints, vulnerable parameters, or function names, are not mentioned beyond the function itself.
Recommendations For GPAC version 2.3-DEV-rev1-g4669ba229-master, consider disabling the avc parse slice function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-23143
DSA-5411-1

Affected Products

Gpac