CVE-2023-1449
published 2023-03-17CVE-2023-1449: A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.37%
29.3th percentile
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gpac | < gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) | gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) |
| gpac | gpac | — | — |
| gpac | gpac | — | — |
| gpac | gpac | >= 0 < 1.0.1+dfsg1-4+deb11u2 | 1.0.1+dfsg1-4+deb11u2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv7.8HIGH
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2w5-7p4r-gxpq: A vulnerability has been found in GPAC 2
ghsa_unreviewed·2023-03-17
CVE-2023-1449 [HIGH] CWE-415 GHSA-x2w5-7p4r-gxpq: A vulnerability has been found in GPAC 2
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
OSV
CVE-2023-1449: A vulnerability has been found in GPAC 2
osv·2023-03-17·CVSS 7.8
CVE-2023-1449 [HIGH] CVE-2023-1449: A vulnerability has been found in GPAC 2
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
Debian
CVE-2023-1449: gpac - A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and class...
vendor_debian·2023·CVSS 5.3
CVE-2023-1449 [MEDIUM] CVE-2023-1449: gpac - A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and class...
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-17
Published