Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43811
HistoryOct 13, 2023 - 7:12 a.m.

Integer Overflow

2023-10-1307:12:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
libgpac.so
dos
integer overflow
q_deccoordonunitsphere
unquantize.c
application crash
dos

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

libgpac.so is vulnerable to Denial Of Service (DOS). The vulnerability is caused by an insufficient validation in the Q_DecCoordOnUnitSphere function of src/bifs/unquantize.c which can lead to an integer overflow. This can result in application crash leading to Denial Of Service (DOS).

CPENameOperatorVersion
libgpac.sole2.0.0
libgpac.sole2.0.0

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%