justdan96 tsMuxer
cpe:2.3:a:justdan96:tsmuxer:*:*:*:*:*:*:*
- <= 2.7.0
A denial-of-service vulnerability has been identified in justdan96 tsMuxer versions prior to 2.7.0. The issue arises in the HevcVpsUnit::setFPS function within hevc.cpp, where improper handling of the track_id argument leads to an assertion failure. This vulnerability requires local access to exploit and affects an unsupported version of the software.
Exploitation of this vulnerability causes an assertion failure, leading to a crash of the tsMuxer application.
The vulnerability can be reproduced by compiling tsMuxer with AddressSanitizer enabled, using Clang as the compiler. After building the application, it can be run with a proof-of-concept file that triggers the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.