GPAC
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*
- 2.5-DEV-rev503-g25797108f-master
A buffer overflow vulnerability has been identified in GPAC version 2.5. This vulnerability allows local attackers to execute arbitrary code. The issue arises from improper handling of certain data, leading to a heap-based buffer overflow. The vulnerability can be exploited by crafting a specific input that is processed by the application, causing it to overwrite memory in a way that executes malicious code.
Exploitation of this vulnerability leads to a heap-based buffer overflow, allowing for arbitrary code execution.
The vulnerability can be reproduced by compiling GPAC with AddressSanitizer enabled, using a specific crafted file as input. This can be done by configuring the build to enable the sanitizer, compiling the application, and then running MP4Box with the crafted file, which triggers the buffer overflow.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.