CVE-2023-23145: High severity gpac mp4box vulnerability
Published Jan 20, 2023
·Updated
GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak in lsrreadrarefull function.
Affected Software
2 affected componentsFixes available
debian/gpac<=0.5.2-426-gc5ad4e4+dfsg5-5, <=2.2.1+dfsg1-3
1.0.1+dfsg1-4+deb11u3
Gpac GPAC=2.2-rev0-gab012bbfb-master
Remediation
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23145?
The severity of CVE-2023-23145 is high with a score of 7.8.
2
What software versions are affected by CVE-2023-23145?
GPAC version 2.2-rev0-gab012bbfb-master is affected by CVE-2023-23145.
3
How can I fix CVE-2023-23145?
To fix CVE-2023-23145, update to GPAC version 1.0.1+dfsg1-4+deb11u3 or GPAC version 2.2.1+dfsg1-3.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23145?
The CWE ID for CVE-2023-23145 is 401.
5
Where can I find more information about CVE-2023-23145?
More information about CVE-2023-23145 can be found at the following references: [GitHub commit](https://github.com/gpac/gpac/commit/4ade98128cbc41d5115b97a41ca2e59529c8dd5f), [Debian Security Advisory](https://www.debian.org/security/2023/dsa-5411), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-23145).