Vulnerability Description
GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gpac | Gpac | 2.3 |
Related Weaknesses (CWE)
References
- https://github.com/ChanStormstout/Pocs/blob/master/gpac_POC/id%3A000000%2Csig%3AThird Party Advisory
- https://github.com/gpac/gpac/issues/2537ExploitIssue Tracking
- https://github.com/ChanStormstout/Pocs/blob/master/gpac_POC/id%3A000000%2Csig%3AThird Party Advisory
- https://github.com/gpac/gpac/issues/2537ExploitIssue Tracking
FAQ
What is CVE-2023-39562?
CVE-2023-39562 is a vulnerability with a CVSS score of 5.5 (MEDIUM). GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (Do...
How severe is CVE-2023-39562?
CVE-2023-39562 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-39562?
Check the references section above for vendor advisories and patch information. Affected products include: Gpac Gpac.