Heap Buffer Overflow in GPAC Affects Multiple Versions of MP4Box
CVE-2023-46927
5.5MEDIUM
What is CVE-2023-46927?
A heap buffer overflow vulnerability exists in GPAC's MP4Box component. This issue arises in the function gf_isom_use_compact_size located in isom_write.c. When handling certain media files, improper handling of memory allocation can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or cause application crashes. Users of GPAC, especially those using MP4Box, are advised to apply necessary updates and monitor security channels for patches addressing this vulnerability.