Vulnerability in MP4Box Could Lead to Null Pointer Dereference
CVE-2024-6063

5.5MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
17 June 2024

Badges

👾 Exploit Exists

What is CVE-2024-6063?

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8767ed0a77c4b02287db3723e92c2169f67c85d5. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-268791.

Affected Version(s)

GPAC 2.5-DEV-rev228-g11067ea92-master

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fantasy (VulDB User)
.