← back
CVE-2023-1449

GPAC av_parsers.c gf_av1_reset_state double free

CVSS 5.3 MEDIUMEPSS 0.4%CWE-415
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
17 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
n/a · GPAC

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →