PT-2024-37357 · Gpac+1 · Gpac+1
Fantasy
·
Published
2024-06-17
·
Updated
2024-09-25
·
CVE-2024-6063
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
GPAC version 2.5-DEV-rev228-g11067ea92-master
Description:
A problematic issue has been found, affecting the function
m2tsdmx on event of the file src/filters/dmx m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack must be approached locally. The exploit has been disclosed to the public and may be used.Recommendations:
Apply a patch to fix this issue, specifically the patch named
8767ed0a77c4b02287db3723e92c2169f67c85d5. As a temporary workaround, consider disabling the m2tsdmx on event function until a patch is available.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Gpac