CVE-2023-42298: Integer Overflow
Published Oct 12, 2023
·Updated
An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the QDecCoordOnUnitSphere function of file src/bifs/unquantize.c.
Affected Software
1 affected component
Gpac GPAC<=2.2.1
Remediation
Patch Available
Event History
Oct 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-42298.
2
What is the severity of CVE-2023-42298?
The severity of CVE-2023-42298 is medium (5.5).
3
How does this vulnerability allow a denial of service?
This vulnerability allows a local attacker to cause a denial of service by exploiting the Q_DecCoordOnUnitSphere function in the unquantize.c file of GPAC.
4
Which version of GPAC is affected by CVE-2023-42298?
GPAC v.2.2.1 and earlier versions are affected by CVE-2023-42298.
5
Is there a fix available for this vulnerability?
A fix for this vulnerability is not specified in the provided information. It is recommended to update to a newer version of GPAC if available, or monitor the GPAC project for future updates and patches.