PT-2023-8942 · Gpac+2 · Gpac+2

Gandalf4A

·

Published

2023-11-15

·

Updated

2024-04-05

·

CVE-2023-48013

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPAC version 2.3-DEV-rev566-g50c2ab06f-master
Description The issue is related to the gf filterpacket del() function in the /gpac/src/filter core/filter.c file of the GPAC multimedia platform. It involves incorrect use of dynamic memory, which can be exploited to impact the confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely, potentially leading to a denial of service.
Recommendations For GPAC version 2.3-DEV-rev566-g50c2ab06f-master, as a temporary workaround, consider disabling the gf filterpacket del() function until a patch is available. Restrict access to the /gpac/src/filter core/filter.c file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Weakness Enumeration

Related Identifiers

BDU:2024-02744
CVE-2023-48013

Affected Products

Debian
Gpac
Red Os