PT-2024-6391 · Gpac+2 · Gpac+2

Published

2024-02-05

·

Updated

2024-09-23

·

CVE-2024-24266

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GPAC version 2.2.1
Description The issue is related to a Use-After-Free (UAF) vulnerability in the dasher configure pid function. This vulnerability can be exploited by a remote attacker to cause a denial of service. The dasher configure pid function is located at /src/filters/dasher.c.
Recommendations For GPAC version 2.2.1, consider disabling the dasher configure pid function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-07445
CVE-2024-24266

Affected Products

Debian
Gpac
Red Os