CVE-2023-46871Missing Release of Memory after Effective Lifetime in Gpac

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 85.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7

Description

GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDgpac/gpac2.3-dev-rev602-ged8424300-master
debiandebian/gpac
mozillamozilla/firefox

Patches

🔴Vulnerability Details

2
GHSA
GHSA-84cp-p2p2-jfjr: GPAC version 22023-12-07
OSV
CVE-2023-46871: GPAC version 22023-12-07

📋Vendor Advisories

3
Debian
CVE-2023-46871: gpac - GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak i...2023
Mozilla
Mozilla Foundation Security Advisory 2023-02: CVE-2022-46871
Mozilla
Mozilla Foundation Security Advisory 2023-03: CVE-2022-46871