Double Free Vulnerability in GPAC by GPAC
CVE-2023-48013

7.8HIGH

Key Information:

Vendor

Gpac

Status
Vendor
CVE Published:
15 November 2023

What is CVE-2023-48013?

A double free vulnerability has been found in GPAC's gf_filterpacket_del function, located in the filter.c file. This flaw allows an attacker to exploit memory management issues, potentially leading to arbitrary code execution or a crash. Users of GPAC version v2.3-DEV-rev566-g50c2ab06f-master are strongly advised to apply the latest patches to mitigate risks associated with this vulnerability. For more details, refer to the discussion on GitHub.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-48013 : Double Free Vulnerability in GPAC by GPAC