First published: Thu Jan 05 2023(Updated: )
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GPAC GPAC | <2.2.0 | |
<2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47093 is a vulnerability in the GPAC MP4box software where a heap use-after-free vulnerability exists via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid.
CVE-2022-47093 can allow an attacker to execute arbitrary code or cause a denial of service by exploiting the heap use-after-free vulnerability.
The severity of CVE-2022-47093 is high with a CVSS score of 7.8.
To mitigate the vulnerability, update GPAC MP4box to a version higher than 2.2.0.
More information about CVE-2022-47093 can be found at the following link: [https://github.com/gpac/gpac/issues/2344](https://github.com/gpac/gpac/issues/2344)