Memory Leak Vulnerability in MP4Box by GPAC
CVE-2023-47384

5.5MEDIUM

Key Information:

Vendor

Gpac

Status
Vendor
CVE Published:
14 November 2023

What is CVE-2023-47384?

A vulnerability has been identified in MP4Box by GPAC, which allows attackers to exploit a memory leak in the function gf_isom_add_chapter located in isomedia/isom_write.c. This flaw can be triggered through specially crafted MP4 files, leading to potential Denial of Service (DoS) conditions, which can disrupt the normal function of applications that utilize this media processing software.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-47384 : Memory Leak Vulnerability in MP4Box by GPAC