PT-2023-18855 · Gpac · Gpac
Published
2023-01-20
·
Updated
2023-05-27
·
CVE-2023-23143
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GPAC version 2.3-DEV-rev1-g4669ba229-master
Description
A buffer overflow issue exists in the
avc parse slice function located in the media tools/av parsers.c file. This issue can be exploited, but details about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited are not provided. The avc parse slice function is vulnerable, but specific technical details about exploitation, such as API endpoints, vulnerable parameters, or function names, are not mentioned beyond the function itself.Recommendations
For GPAC version 2.3-DEV-rev1-g4669ba229-master, consider disabling the
avc parse slice function as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpac