漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
Vulnerability Description
A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the component MP4Box. This manipulation of the argument nalu_out_bs causes double free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: f29f955f2a3b5e8e507caad3e52319f961bf37bf. To fix this issue, it is recommended to deploy a patch.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
双重释放
Vulnerability Title
GPAC 缓冲区错误漏洞
Vulnerability Description
GPAC是GPAC团队开源的一款开源的多媒体框架。 GPAC 2.5-DEV之前版本存在安全漏洞,该漏洞源于MP4Box组件中src/isomedia/avc_ext.c文件的gf_isom_nalu_sample_rewrite函数对参数nalu_out_bs的操作导致双重释放,可能允许本地攻击者利用该漏洞。
CVSS Information
N/A
Vulnerability Type
N/A