PT-2024-6390 · Gpac+2 · Gpac+2

Published

2024-02-05

·

Updated

2024-09-23

·

CVE-2024-24265

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions gpac version 2.2.1
Description The issue is related to a memory leak in the gf filter pid merge properties internal function, specifically via the dst props variable. This can be exploited by a remote attacker to cause a denial of service. The memory leak occurs due to the lack of memory release after its effective term of service.
Recommendations For gpac version 2.2.1, as a temporary workaround, consider disabling the gf filter pid merge properties internal function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2024-07444
CVE-2024-24265

Affected Products

Debian
Red Os
Gpac