Vulnerability in MP4Box Could Lead to Use After Free (CVE-2023-268792)
CVE-2024-6064

5.5MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
17 June 2024

Badges

👾 Exploit Exists

What is CVE-2024-6064?

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is f4b3e4d2f91bc1749e7a924a8ab171af03a355a8/c1b9c794bad8f262c56f3cf690567980d96662f5. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-268792.

Affected Version(s)

GPAC 2.5-DEV-rev228-g11067ea92-master

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fantasy (VulDB User)
.
CVE-2024-6064 : Vulnerability in MP4Box Could Lead to Use After Free (CVE-2023-268792)