CVE-2024-6061

medium

Description

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is 20c0f29139a82779b86453ce7f68d0681ec7624c. It is recommended to apply a patch to fix this issue. The identifier VDB-268789 was assigned to this vulnerability.

References

https://vuldb.com/?submit.356308

https://vuldb.com/?id.268789

https://vuldb.com/?ctiid.268789

https://github.com/user-attachments/files/15801058/poc1.zip

https://github.com/gpac/gpac/issues/2871

https://github.com/gpac/gpac/commit/20c0f29139a82779b86453ce7f68d0681ec7624c

Details

Source: Mitre, NVD

Published: 2024-06-17

Updated: 2024-09-25

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

CVSS v4

Base Score: 4.8

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium