Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75mr-r5qh-vfwp

Опубликовано: 27 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.9
CVSS3: 5.3

Описание

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.

EPSS

Процентиль: 2%
0.00113
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.

CVSS3: 5.3
nvd
3 месяца назад

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.

CVSS3: 5.3
debian
3 месяца назад

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f ...

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость функции elng_box_read() файла src/isomedia/box_code_base.c упаковщика MP4Box мультимедийной платформы GPAC, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 5.3
redos
около 1 месяца назад

Уязвимость gpac

EPSS

Процентиль: 2%
0.00113
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119