Buffer Overflow Vulnerability in FLVMeta from NoirT
CVE-2023-36243

7.8HIGH

Key Information:

Vendor

Flvmeta

Status
Vendor
CVE Published:
22 June 2023

What is CVE-2023-36243?

The FLVMeta version 1.2.1 is susceptible to a buffer overflow vulnerability that can be exploited through the xml_on_metadata_tag_only function in the dump_xml.c file. This flaw allows for potential unauthorized access and can be leveraged by attackers to execute arbitrary code or cause unexpected behavior in the application. It is crucial for users of FLVMeta to promptly update their software to mitigate the associated risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.