Lucene search

K
redosRedosROS-20230621-03
HistoryJun 21, 2023 - 12:00 a.m.

ROS-20230621-03

2023-06-2100:00:00
redos.red-soft.ru
7
gpac
multimedia platform
vulnerability
null pointer dereferencing
stack overflow
denial of service
arbitrary code execution
unix

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.8%

A vulnerability in the GPAC multimedia platform is related to null pointer dereferencing in
gf_isom_fragment_add_sample_exisomedia/movie_fragments.c:2883. Exploitation of the vulnerability could allow
an attacker to cause a denial of service (DoS), causing the application to crash or render it unresponsive.

The GPAC multimedia platform vulnerability is related to a stack overflow in the xml_sax_parse function in the
src/utils/xml_parser.c. Exploitation of the vulnerability could allow an attacker to cause a denial of
denial of service or arbitrary code execution.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64gpac< 0.7.1-3UNKNOWN

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.8%