PT-2024-37356 · Gpac+2 · Gpac+2

Fantasy

·

Published

2024-06-17

·

Updated

2025-04-30

·

CVE-2024-6062

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: GPAC version 2.5-DEV-rev228-g11067ea92-master
Description: A problematic issue was found, affecting the swf svg add iso sample function of the src/filters/load text.c file in the MP4Box component. This issue leads to a null pointer dereference and requires local access to exploit. The exploit has been publicly disclosed.
Recommendations: For GPAC version 2.5-DEV-rev228-g11067ea92-master, apply the patch identified as 31e499d310a48bd17c8b055a0bfe0fe35887a7cd to fix this issue. As a temporary workaround, consider disabling the swf svg add iso sample function until the patch is applied.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-07586
CVE-2024-6062

Affected Products

Debian
Gpac
Red Os