CVE-2024-6064Use After Free in Gpac

CWE-416Use After Free4 documents4 sources
Severity
4.8MEDIUMNVD
EPSS
0.0%
top 89.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 17

Description

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is f4b3e4d2f91bc1749e7a924a8ab171af03a355a8/c1b9c794bad8f262c56f3cf690567980d96662f5. It is recomm

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages3 packages

CVEListV5gpac/gpac2.5-DEV-rev228-g11067ea92-master
NVDgpac/gpac2.5-dev-rev288-g11067ea92-master
debiandebian/gpac

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6r4x-gvmf-4gw2: A vulnerability was found in GPAC 22024-06-17
OSV
CVE-2024-6064: A vulnerability was found in GPAC 22024-06-17

📋Vendor Advisories

1
Debian
CVE-2024-6064: gpac - A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been ...2024
CVE-2024-6064 — Use After Free in Gpac | cvebase