PT-2026-53193 · Gpac+1 · Gpac+1
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GPAC versions prior to 26.02.1
Description
A buffer overflow exists in the ISOBMFF Parser component within the
src/utils/base encoding.c file. A local attacker can execute a manipulation involving highly compressed data to trigger this issue. The flaw is addressed by implementing a check on the inflate output size, which triggers an error if the output exceeds 32 times the input size.Recommendations
Apply the patch 297f2d8d1f493d8b241330533cd47f7da758aeb3 to remediate the issue.
Exploit
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gpac
Red Os