
Cloud Vulnerability DB
A community-led vulnerabilities database
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a segmentation fault (SEGV) vulnerability in the gfmediachangepl function located in /afltest/gpac/src/mediatools/isom_tools.c at line 3293. The vulnerability was discovered in October 2023 and affects the MP4Box component of GPAC (NVD, Debian Tracker).
The vulnerability is triggered by a write memory access to an invalid address (0x000000000002) pointing to the zero page. The issue occurs in the gfmediachange_pl function when processing certain MP4 files. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD).
When exploited, this vulnerability can cause the application to crash through a segmentation fault, potentially leading to a denial of service condition. The vulnerability requires local access and user interaction to be exploited (GitHub Issue).
A fix has been implemented through a null guard check in the gfmediachange_pl function. The patch is available in commit 0753bf6d867343a80a044bf47a27d0b7accc8bf1 (GPAC Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."