PT-2023-3406 · Gpac+2 · Gpac+2
Published
2018-12-19
·
Updated
2023-06-22
·
CVE-2023-2840
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
gpac versions prior to 2.2.2
Description
The issue is related to a NULL Pointer Dereference in the gpac library, specifically in the
gf isom fragment add sample ex() function located in isomedia/movie fragments.c. This could allow a remote attacker to execute arbitrary code.Recommendations
For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue.
As a temporary workaround, consider disabling the
gf isom fragment add sample ex() function until a patch is available.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Os
Gpac